fix(auth): scope signOut to local session only
Release desktop app / build (, windows-latest) (push) Has been cancelled
Release desktop app / build (--target universal-apple-darwin --bundles app,updater, macos-14) (push) Has been cancelled

This commit is contained in:
2026-04-19 20:11:08 +02:00
parent cf3fef6936
commit 05c962d46f
3 changed files with 7 additions and 3 deletions
+5 -1
View File
@@ -86,7 +86,11 @@ export async function completeSessionFromUrl(
}
export async function signOut(client: AppSupabaseClient): Promise<void> {
const { error } = await client.auth.signOut();
// `scope: 'local'` only ends the session in THIS client. Without it Supabase
// defaults to 'global', which invalidates the user's refresh tokens
// everywhere — meaning a logout in the browser would also kick the desktop
// app (and vice versa) the next time it tries to refresh its token.
const { error } = await client.auth.signOut({ scope: 'local' });
if (error) throw error;
}