Stop setting the redundant TabAuthToken cookie - #597
Merged
spicermatthews merged 1 commit intoApr 23, 2026
Merged
Conversation
v5 used to read TabAuthToken — a duplicate of the Firebase ID token that we set client-side on every tokenChangedHandler invocation. v5 now reads the same idToken directly from the dotted TabAuth.AuthUserTokens cookie that next-firebase-auth manages server-side, so the duplicate is unnecessary. Removing TabAuthToken shrinks every authenticated request to tab.gladly.io by 1-2 KB, pulling users away from CloudFront's 32 KB request-size ceiling and the resulting 494 errors. Also explicitly deletes any pre-existing TabAuthToken cookie on every tokenChangedHandler call. The original cookie was set with a 1-year expiry, so without an explicit deletion it would linger in users' browsers for up to a year. Active users will get the cookie cleared on their next page load. Updated test confirms deleteCookie is called in both the authed and unauthed branches. The misleading comment about CloudFront not supporting dotted cookies has been removed; we verified empirically that CloudFront forwards dotted cookies fine when whitelisted in the origin request policy.
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Stops setting
TabAuthTokenintokenChangedHandlerand explicitly deletes any pre-existingTabAuthTokencookie. This is part 2 of the migration to retire the duplicate Firebase auth cookie that v5 used to read.Why
v5 used to read
TabAuthToken— a 1-2 KB duplicate of the Firebase ID token that we wrote client-side viadocument.cookiefor v5's benefit. As of tab-v5#150, v5 reads the same idToken directly from the dottedTabAuth.AuthUserTokenscookie thatnext-firebase-authalready manages server-side viaapiLogin. With both reads done from the same source, the client-side duplicate is dead weight.Why this matters
CloudFront access logs show ~3.7% of users are within 3 KB of CloudFront's 32 KB request-size limit and ~8% are over it (most CloudFront edges seem lenient, but the strict ones return 494 errors that users have been reporting). Removing this 1-2 KB cookie pulls borderline users out of 494 territory.
Changes
setCookie('TabAuthToken', ...)call withdeleteCookie('TabAuthToken', { path: '/' })so existing browsers actively clear the cookie on the nexttokenChangedHandlerinvocation (rather than leaving it to expire over up to 1 year).nextYearDatecalculation.\$_COOKIErewriting dots to underscores, which v5 now bypasses by reading\$_SERVER['HTTP_COOKIE']directly.deleteCookieis called in both authed and unauthed branches.v5 fallback safety
tab-v5#150 deployed with a fallback: if
TabAuth.AuthUserTokensisn't readable for any reason, v5 falls back toTabAuthToken. Production logs show the new cookie is being read successfully for active v4 users (the population that actually loads tab-web). For users who don't load tab-web (Chrome extension API calls, v1 users) the fallback continues to apply — they still have whatever staleTabAuthTokenthey had previously, and this PR's deletion only fires when a user does load tab-web.Test plan
TabAuthTokenis gone from the cookie list whileTabAuth.AuthUserTokensremainsAuth: fell back to TabAuthTokenfrom/v5/*paths (most fallback should remain on/api/v1/tab/logfrom extension calls — that's expected and fine)Follow-up (not in this PR)
TabAuthTokenviadocument.cookie— those are legacy and now duplicative.TabAuthTokenfallback path in v5 and drop the cookie from CloudFront'sv5-request-policywhitelist after confirming the fallback rate is at zero or near-zero.