From 8b2b6ffb6f44836c3365694b7548c7338ba7b6c1 Mon Sep 17 00:00:00 2001 From: VickyStash Date: Mon, 27 Jul 2026 14:54:12 +0200 Subject: [PATCH 1/2] Extract authToken from gap-deferred sign-in while OpenApp is in-flight --- src/libs/actions/OnyxUpdateManager/index.ts | 3 +++ 1 file changed, 3 insertions(+) diff --git a/src/libs/actions/OnyxUpdateManager/index.ts b/src/libs/actions/OnyxUpdateManager/index.ts index 2a7081009ea3..f927e2f41664 100644 --- a/src/libs/actions/OnyxUpdateManager/index.ts +++ b/src/libs/actions/OnyxUpdateManager/index.ts @@ -154,6 +154,9 @@ function handleMissingOnyxUpdates(onyxUpdatesFromServer: O // we don't have base state of the app (reports, policies, etc.) setup. If we apply this update, // we'll only have them overwritten by the openApp response. So let's skip it and return. if (isLoadingApp) { + // If one of these onyx updates is for the authToken, update it now because our current authToken is probably invalid. + updateAuthTokenIfNecessary(onyxUpdatesFromServer); + // When ONYX_UPDATES_FROM_SERVER is set, we pause the queue. Let's unpause // it so the app is not stuck forever without processing requests. unpauseSequentialQueue(); From 785eb37f95edafa4692c02de1071a1d18491c5fd Mon Sep 17 00:00:00 2001 From: VickyStash Date: Tue, 28 Jul 2026 11:33:36 +0200 Subject: [PATCH 2/2] Clear the consumed deferred sign-in update after extracting its authToken --- src/libs/actions/OnyxUpdateManager/index.ts | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/src/libs/actions/OnyxUpdateManager/index.ts b/src/libs/actions/OnyxUpdateManager/index.ts index f927e2f41664..4bef25f9e8a3 100644 --- a/src/libs/actions/OnyxUpdateManager/index.ts +++ b/src/libs/actions/OnyxUpdateManager/index.ts @@ -157,6 +157,10 @@ function handleMissingOnyxUpdates(onyxUpdatesFromServer: O // If one of these onyx updates is for the authToken, update it now because our current authToken is probably invalid. updateAuthTokenIfNecessary(onyxUpdatesFromServer); + // Nothing reads this key again once we return, but it is persisted, so a restart would replay it and + // could write a now-stale authToken over a newer session. Drop the consumed copy. + Onyx.set(ONYXKEYS.ONYX_UPDATES_FROM_SERVER, null); + // When ONYX_UPDATES_FROM_SERVER is set, we pause the queue. Let's unpause // it so the app is not stuck forever without processing requests. unpauseSequentialQueue();