Do not reset the auth cookie on every request to `GET /login`

fix(API): do not reset the auth cookie on every request to `GET /login` (#4459)
Do not reset the auth cookie on every request to `GET /login`fixreset auth cookie every request get

Committed by netroy

commit message
fix(API): do not reset the auth cookie on every request to `GET /login` (#4459)

The cookie and the JWT refresh is already handled in `refreshExpiringCookie` middleware, which only updates the cookie 3 days before the expiration.
 
The middleware also uses `issueCookie`, which ensures that attributes like `sameSite` and `httpOnly` are correctly set on the cookie.

Editor assessment

The subject is exemplary: it names the exact endpoint, GET /login, and the precise misbehavior, the auth cookie being reset on every request. The fix type and API scope are accurate. The body then teaches the surrounding design in two sentences: refresh-expiring-cookie middleware already handles the JWT refresh and only rewrites the cookie three days before expiration, and issueCookie guarantees attributes like sameSite and httpOnly are set correctly. A reader finishes with a full model of the auth flow and why the removal is safe, which is exactly what a body exists to teach. Style is clean and the PR reference well formed. A genuine exemplar.

Browse categories

More fix examples · Back to search