[QA] §N OIDC / next-gen auth (MSC3861): login, persistence, refresh, logout revoke, account deep-link, password regression #183
Open
opened 2026-09-17 23:24:09 -04:00 by jared
·
0 comments
No Branch/Tag Specified
lotus
update-packages
sw-fix
read-me-update
image-path-changes
dm-calls
fix-2469
renovate/element-hq-element-call-embedded-0.x
renovate/npm-i18next-http-backend-vulnerability
renovate/npm-vite-vulnerability
dev
docs-update
more-theme
fix-257
imporve-thread-reply
revert-2402-improve-menu-congestion
mxidColor-toggle
update-sw-main-msg
v4.11.1
v4.10.5
v4.10.4
v4.10.3
v4.10.2
v4.10.1
v4.10.0
v4.9.1
v4.9.0
v4.8.1
v4.8.0
v4.7.1
v4.7.0
v4.6.0
v4.5.1
v4.5.0
v4.4.0
v4.3.2
v4.3.0
v4.2.3
v4.2.2
v4.2.1
v4.2.0
v4.1.0
v4.0.3
v4.0.0
v3.2.0
v3.1.0
v3.0.0
v2.2.6
v2.2.5
v2.2.4
v2.2.3
v2.2.2
v2.2.1
v2.2.0
v2.1.3
v2.1.2
v2.1.1
v2.1.0
v2.0.4
v2.0.3
v2.0.2
v2.0.1
v2.0.0
v1.8.2
v1.8.1
v1.8.0
v1.7.0
v1.6.1
v1.6.0
v1.5.1
v1.5.0
v1.4.0
v1.3.2
v1.3.1
v1.3.0
v1.2.1
v1.2.0
v1.1.0
v1.0.0
Labels
Clear labels
a11y
area: appearance
area: auth-session
area: build-ci
area: calls
area: desktop
area: media
area: messaging
area: mobile
area: moderation
area: navigation
area: notifications
area: settings
area: threads
bug
dependencies
docs
duplicate
enhancement
help wanted
invalid
needs-human-review
performance
planning
priority: critical
priority: high
priority: low
priority: medium
qa
question
research
security
tech-debt
ux
wontfix
Accessibility: keyboard, screen reader, contrast, motion
Client area: appearance
Client area: auth-session
Client area: build-ci
Client area: calls
Client area: desktop
Client area: media
Client area: messaging
Client area: mobile
Client area: moderation
Client area: navigation
Client area: notifications
Client area: settings
Client area: threads
Something is not working
Third-party package versions and advisories
README / LOTUS_* docs wrong or missing
This issue or pull request already exists
New feature
Need some help
Something is wrong
Re-render storms, leaks, heavy work on hot paths
Data loss, security hole, or crash on a main path
Broken feature or serious usability problem
Minor issue or polish
Wrong behaviour in an edge case or notable degradation
Manual QA: shipped, needs a human in a real environment
More information is needed
XSS, unsafe URLs, data leaks, auth/session
Code health, dead code, fragile patterns
Usability or visual inconsistency
This won't be fixed
Milestone
No items
No Milestone
Manual QA backlog
Projects
Clear projects
No projects
No Assignees
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: LotusGuild/cinny#183
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Migrated from
LOTUS_TESTING.md§N on 2026-09-17 — the file is now reference-only.How to report: tick each item as it passes; on FAIL comment with what you saw vs expected, browser/OS, web (chat.lotusguild.org) vs desktop (Tauri), theme, and any browser-console errors. Screenshots for anything visual.
Checklist
The Lotus client can now sign into OIDC-native homeservers (ones that delegate
auth to a Matrix Authentication Service / MAS), e.g. mozilla.org. lotusguild's
own server is not MSC3861, so test EITHER against a local MAS dev loop
(full setup in
dev/oidc-test/README.md— docker-compose + Synapsemsc3861delta + a
config.jsonoverride) OR against mozilla.org with a real account.N1. OIDC login flow (the core test) — needs a MAS homeserver
localhost:8008, ormozilla.org).chat.mozilla.org).…/auth/oidc/callback→ a brief "Signing you in…" spinner → you land in the app, logged in.Expected: no console CSP violations; you reach the room list as the OIDC user.
N2. Session persists across reload (token storage)
After N1, hard-refresh the page.
Expected: you stay logged in — the OIDC session (access + refresh token + issuer/clientId/claims) was persisted (
cinny_refresh_token,cinny_oidc_*keys in localStorage).N3. Token refresh (long-lived session)
Leave the session past the access-token lifetime (MAS default is short — or revoke the access token in the MAS admin UI to force a 401).
Expected: the client refreshes transparently (no logout); the stored access token rotates (reactive 401 refresh via the wired
OidcTokenRefresher).N4. Logout revokes at the issuer
Log out from Settings.
Expected: back to login; OIDC tokens are revoked at the issuer's
revocation_endpoint(best-effort) and allcinny_*/cinny_oidc_*keys are cleared. Logging back in works.N5. Account-management deep-link
Settings → Account.
Expected: on an OIDC server a "Manage account" card appears (opens the provider's account page in a new tab). On a non-OIDC server (lotusguild) the card is absent.
N6. Non-OIDC regression — password login unchanged
Log into matrix.lotusguild.org (password) and matrix.org.
Expected: identical to before — username/password form (+ SSO button where offered). The OIDC path only activates when discovery advertises an issuer, so nothing changes for these servers.