This commit is contained in:
kim
2026-05-04 17:58:17 +09:00
parent fc88bda24b
commit 9714d4b50c
63 changed files with 1323 additions and 197 deletions
+34
View File
@@ -5821,6 +5821,26 @@ async function api(path, opts = {}) {
return data;
}
const LAST_USER_KEY = 'cherryclaw_last_user';
function clearLocalUserState(reason) {
try {
localStorage.removeItem(CHAT_SESSIONS_KEY);
localStorage.removeItem(AGENT_SESSION_KEY);
} catch {}
try {
chatSessions = [];
activeChatSessionId = null;
} catch {}
setAgentSessionId(generateSessionId());
// Rebuild a fresh "New chat" + re-render so the UI does not briefly
// display the previous user's session list before the wipe takes effect.
try { if (typeof loadChatSessions === 'function') loadChatSessions(); } catch {}
try { if (typeof renderSessionsList === 'function') renderSessionsList(); } catch {}
try { if (typeof renderMessages === 'function') renderMessages(); } catch {}
console.log(`[auth] cleared local session state (${reason})`);
}
async function checkAuth() {
try {
const res = await fetch('/api/auth/status');
@@ -5835,6 +5855,16 @@ async function checkAuth() {
}
if (data.authenticated && data.username) {
currentUser = { username: data.username, role: data.role };
// Multi-user safety: if a different user was logged in on this browser
// before, wipe the cached session list & active sessionId so the
// incoming user does not reuse the previous user's chat IDs.
const lastUser = (localStorage.getItem(LAST_USER_KEY) || '').trim();
if (lastUser && lastUser !== data.username) {
clearLocalUserState(`user changed: ${lastUser} -> ${data.username}`);
}
try { localStorage.setItem(LAST_USER_KEY, data.username); } catch {}
// Show user pill with username
const pill = document.getElementById('user-info-pill');
const nameEl = document.getElementById('user-info-name');
@@ -5852,6 +5882,10 @@ async function logout() {
try {
await fetch('/api/auth/logout', { method: 'POST', credentials: 'same-origin' });
} catch (e) { /* ignore network errors */ }
// Wipe cached chat list / sessionId so a different user logging in next
// does not inherit any of this user's session IDs.
clearLocalUserState('logout');
try { localStorage.removeItem(LAST_USER_KEY); } catch {}
window.location.href = '/login.html';
}