diff --git a/apps/desktop/src/components/boot-failure-overlay.test.tsx b/apps/desktop/src/components/boot-failure-overlay.test.tsx index e9148c99e0..97a685f684 100644 --- a/apps/desktop/src/components/boot-failure-overlay.test.tsx +++ b/apps/desktop/src/components/boot-failure-overlay.test.tsx @@ -203,7 +203,8 @@ describe('BootFailureOverlay', () => { fireEvent.click(await screen.findByRole('button', { name: /sign in/i })) await waitFor(() => expect(cloudAgentSignIn).toHaveBeenCalledWith(gatewayUrl)) - expect(logout).toHaveBeenCalledWith(gatewayUrl) + // The ladder owns the logout: exactly one drop of this gateway's cookies. + expect(logout).toHaveBeenCalledExactlyOnceWith(gatewayUrl) expect(cloudStatus).toHaveBeenCalledTimes(1) expect(cloudLogin).toHaveBeenCalledTimes(1) expect(nativeLogin).not.toHaveBeenCalled() diff --git a/apps/desktop/src/components/boot-failure-overlay.tsx b/apps/desktop/src/components/boot-failure-overlay.tsx index b3364586ad..a3a7eb1000 100644 --- a/apps/desktop/src/components/boot-failure-overlay.tsx +++ b/apps/desktop/src/components/boot-failure-overlay.tsx @@ -207,11 +207,11 @@ export function BootFailureOverlay() { try { const desktop = window.hermesDesktop - await desktop?.oauthLogoutConnectionConfig?.(remoteReauth.url) - let connected: boolean if (connectionConfig?.mode === 'cloud' && desktop?.cloud) { + // The ladder drops this gateway's lapsed cookies itself — logging out + // here as well would fire the IPC twice for the cloud path. const outcome = await reestablishCloudAgentSession(desktop, remoteReauth.url) if (outcome === 'portal-incomplete') { @@ -226,6 +226,8 @@ export function BootFailureOverlay() { connected = true } else { + await desktop?.oauthLogoutConnectionConfig?.(remoteReauth.url) + connected = (await desktop?.oauthLoginConnectionConfig(remoteReauth.url))?.connected === true }