Skip to content

easyiq: verify the confirm step cannot itself move the session child #72

Description

@nickknissen

The #68 fix confirms each SwitchChild by calling AuthenticateAulaUser and comparing the child it echoes back (confirm_easyiq_session_child in src/aula/widgets/client.py).

The same investigation showed that AuthenticateAulaUser re-resolves the child, and that re-authenticating with a narrowed x-childfilter moves the session to that child. The confirm step sends the full child list, and the working assumption is that this leaves the session where SwitchChild put it. That held in the reporter's runs but was never tested directly.

To verify against a live portal: switch to child A, call the confirm with the full child list twice in a row, and check the second answer still says child A. If the confirm can move the session, the confirm-then-read ordering inside the lock needs rethinking.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions