Make *** cookie client-accessible & validate OTK directly in Next.js
Major Simplifications: - *** cookie is now client-accessible (httpOnly: false) - Both Next.js and Java can read the cookie directly - Cookie expires in 30 minut...
Reduce *** ID length from 512 to 128 characters
Changes: - ***_ID_LENGTH: 512 -> 128 (64 bytes of entropy) - Updated all documentation and comments - Updated logging to show full 128-char ID - OTK length rema...
Fix build error and change *** length to 128 chars
Build Fixes: - Escape apostrophe in validate page (') - Add searchParams dependency to useEffect *** Length Change: - Update expected *** length from 512 ...
Add comprehensive debugging UI to validate page
- Show component render count and validation attempt count - Display OTK information and length validation - Show retrieved *** ID (512 chars) when successful -...
Increase *** ID length to 512 characters for enhanced security
- *** ID: 512-char hex string (256 bytes of secure random data) - OTK ID: 64-char hex string (32 bytes - unchanged) - Updated generateSecureHexString() to accep...
Fix OTK validation duplicate calls issue
- Add useRef to track validation attempts - Prevent duplicate API calls (critical for one-time keys) - Change useEffect deps to empty array (run once on mount) ...
Update OTK validation to use new *** session model
- Extract ***Id from JSON response body (not Set-Cookie header) - SecurityService now returns { success, message, ***Id } - Set *** cookie with 64-char GUID fro...
Implement new *** session model with 64-char GUID
- Add KSessionService for simplified session management - *** ID is now a 64-char hex string (not encoded KToken) - Redis key format: ***<64-char-guid> - Redis ...
Add no-cache headers and extensive logging to debug user-info loading
Always call API to fetch user info, don't check HttpOnly cookie client-side
Use session cookies instead of persistent cookies with maxAge
Replace RoleRightType.valueOf with manual lookup of static instances
Use property access instead of method calls for RoleRightType and ServiceType
Add usernameAlias, memberEmail, and countryAbbreviation to user-info endpoint
Extract session ID from upstream and set *** cookie explicitly for internal domain
Remove cookie domain attribute for proper per-subdomain cookie setting
Update cookie name from KAMOSESH to *** throughout kamo-internal
Update session naming - use *** cookie and SESSION<guid> Redis keys per SSO specification
Simplify Redis config to use master only, avoiding READONLY errors
Move eslint suppression to correct line for redisReplica assignment
Suppress eslint warning for redisReplica (reserved for future read operations)
Implement Redis read/write splitting - writes to master (10.8.0.1), reads from replica
Implement Redis read/write splitting - writes to master (10.8.0.1), reads from replica
Use shared library Redis configuration instead of local config
Add shared Redis read/write splitting configuration - writes to master, reads from replica
Implement Redis read/write splitting - writes to master (10.8.0.1), reads from replica
Implement Redis read/write splitting - writes to master (10.8.0.1), reads from replica
Trigger rebuild with latest shared library (MemberRightsApplied column name fix)
Update password pepper to match KamoInitializerService - Set pepper to 'f09kf32j0sdfsdfd' to ensure password hashing consistency across services
Password hash generator endpoint for testing/admin - POST **************** to create proper PBKDF2 hashes
Better error handling and logging for API responses - Parse both JSON and text responses with detailed logging
Provide specific error messages for account validation failures - Users now see exact reason **************** instead of generic message
Like what you see shipping?
All of it arrives in your workspace on its own. Start on the free plan and read this page again in a month.
