Skip to content

fix(sessions): reject a duplicate session id in FirestoreSessionService - #1554

Closed
copybara-service[bot] wants to merge 1 commit into
mainfrom
test_986983990
Closed

copybara-service[bot] wants to merge 1 commit into
mainfrom
test_986983990

Conversation

@copybara-service

@copybara-service copybara-service Bot commented Sep 24, 2026 •

Copy link
Copy Markdown

fix(sessions): reject a duplicate session id in FirestoreSessionService

  • createSession used to overwrite a session whose id was already in use,
    keeping its old events. It now fails with SessionException; to reuse an id,
    delete the session first.
  • Session ids are unique per user across apps, so an id the same user already
    has under another app is rejected too.
  • New session documents store a createToken field, so a create that the
    client retried after a lost reply is not reported as a duplicate.

- `createSession` used to overwrite a session whose id was already in use,
  keeping its old events. It now fails with `SessionException`; to reuse an id,
  delete the session first.
- Session ids are unique per user across apps, so an id the same user already
  has under another app is rejected too.
- New session documents store a `createToken` field, so a create that the
  client retried after a lost reply is not reported as a duplicate.

PiperOrigin-RevId: 986983990
@copybara-service copybara-service Bot closed this Sep 28, 2026
@copybara-service
copybara-service Bot deleted the test_986983990 branch September 28, 2026 14:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant