Skip to content

Change cookie expiration date when Impersonating - #153

Merged
jszobody merged 2 commits into
stechstudio:masterfrom
LuizCristino:patch-1
May 11, 2026
Merged

jszobody merged 2 commits into
stechstudio:masterfrom
LuizCristino:patch-1

Conversation

@LuizCristino

Copy link
Copy Markdown
Contributor

This change resolves an odd behavior that occurs when there are multiple panels with multiple authentication guards.

When you switch from one panel to another after invalidating the token, Laravel attempts to refresh the current token with the remember me token.

This invalidates the token for the other panel, breaking the impersonating banner.

This change resolves an odd behavior that occurs when there are multiple panels with multiple authentication guards.

When you switch from one panel to another after invalidating the token, Laravel attempts to refresh the current token with the remember me token. 

This invalidates the token for the other panel, breaking the impersonating banner.

@jszobody jszobody left a comment •

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for the PR! The diagnosis matches Laravel's remember-me token rotation behavior — when a different guard hits the remember path, it rotates the DB token and invalidates the value we stashed in the session, breaking leave(). Clearing the cookie at enter() time avoids that, and extractAuthCookieFromSession() restores it on leave() so the user's remember-me survives the round trip.

One small ask before merging — could you swap the manual -2628000 for cookie()->forget()? Same effect, no magic number, and it stays consistent with the cookie()/session() helper style used elsewhere in this class:

cookie()->queue(cookie()->forget($key));

We'll handle adding test coverage for the multi-panel / multi-guard scenario on our side.

Remove magic number and use laravel methods to be more consistent.
@LuizCristino

Copy link
Copy Markdown
Contributor Author

@jszobody Thank you for your time. I didn't know about the cookie forget method; thanks for pointing it out.

I made the suggested changes.

@jszobody
jszobody merged commit 1b75c9b into stechstudio:master May 11, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants