[fix] require an account to subscribe to the alert and manager streams - #4272
Open
Duansg wants to merge 5 commits into
Open
[fix] require an account to subscribe to the alert and manager streams#4272Duansg wants to merge 5 commits into
Duansg wants to merge 5 commits into
Conversation
zqr10159
previously approved these changes
Jul 30, 2026
zqr10159
left a comment
Member
There was a problem hiding this comment.
Reviewed against the 1.9.0 pre-release alert and manager SSE findings. The streams are removed from the authentication exclusions, the browser sends bearer authorization, and emitter lifetime/capacity are bounded. The focused local contracts pass (10 tests) and CI is green.
The alert and manager streams moved from `EventSource` to a `fetch` reader so the bearer token could travel with the request. `EventSource` reconnects on its own; the reader did not, and the same change bounds an emitter's life to thirty minutes. Together that meant the notification bell and the alert center stopped receiving anything half an hour in, until the page was reloaded. `AuthorizedSseService` now re-establishes a dropped stream itself, with an exponential backoff from one second to thirty, reset once a connection is up. The token is read on every attempt so a refreshed one is picked up. A 401 or 403 still ends the observable: reconnecting cannot change that answer and retrying would only hammer the endpoint. This mirrors `log-stream.component.ts`, which already reads an authorized stream through `fetch` and already reconnects. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What's changed?
Require authentication for the alert/manager SSE streams; the front end switches to fetch so it can carry credentials, plus a connection timeout and a concurrency cap.
Checklist
Add or update API