fix(desktop): let the cloud ladder own the reauth logout

The boot overlay dropped this gateway's cookies before branching, and
reestablishCloudAgentSession drops them again as its first rung, so the
cloud path fired oauthLogoutConnectionConfig twice per sign-in. Move the
logout into the native-OAuth branch that still needs it; the overlay's
cloud test now pins exactly one call.
This commit is contained in:
Austin Pickett
2026-09-24 10:59:01 -04:00
parent eb9ee9cacc
commit 645da6561c
2 changed files with 6 additions and 3 deletions

View File

@@ -203,7 +203,8 @@ describe('BootFailureOverlay', () => {
fireEvent.click(await screen.findByRole('button', { name: /sign in/i }))
await waitFor(() => expect(cloudAgentSignIn).toHaveBeenCalledWith(gatewayUrl))
expect(logout).toHaveBeenCalledWith(gatewayUrl)
// The ladder owns the logout: exactly one drop of this gateway's cookies.
expect(logout).toHaveBeenCalledExactlyOnceWith(gatewayUrl)
expect(cloudStatus).toHaveBeenCalledTimes(1)
expect(cloudLogin).toHaveBeenCalledTimes(1)
expect(nativeLogin).not.toHaveBeenCalled()

View File

@@ -207,11 +207,11 @@ export function BootFailureOverlay() {
try {
const desktop = window.hermesDesktop
await desktop?.oauthLogoutConnectionConfig?.(remoteReauth.url)
let connected: boolean
if (connectionConfig?.mode === 'cloud' && desktop?.cloud) {
// The ladder drops this gateway's lapsed cookies itself — logging out
// here as well would fire the IPC twice for the cloud path.
const outcome = await reestablishCloudAgentSession(desktop, remoteReauth.url)
if (outcome === 'portal-incomplete') {
@@ -226,6 +226,8 @@ export function BootFailureOverlay() {
connected = true
} else {
await desktop?.oauthLogoutConnectionConfig?.(remoteReauth.url)
connected = (await desktop?.oauthLoginConnectionConfig(remoteReauth.url))?.connected === true
}