fix: handle session cookies with no expiry - #1009
Merged
Merged
Conversation
ricellis
reviewed
Aug 26, 2026
ricellis
approved these changes
Aug 28, 2026
veronika-alraheem
force-pushed
the
1361-session-cookie-no-expiry
branch
from
August 28, 2026 08:18
996d7db to
ba022ca
Compare
veronika-alraheem
force-pushed
the
1361-session-cookie-no-expiry
branch
from
August 28, 2026 08:21
ba022ca to
cf915cf
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
PR summary
When using session cookies there is no
expiresormax-ageattribute available. This raises aTypeErrorwhen we try to compare theNoneto the current time.Fixes i1361
PR Checklist
Please make sure that your PR fulfills the following requirements:
Angular Commit Message Guidelines.
PR Type
What is the current behavior?
When authenticating with a session cookie, the AuthSession cookie has no
ExpiresorMax-Ageattribute. The requests library parses cookie.expires asNonein this case. This raised aTypeErroras soon asibm_cloud_sdk_core's TokenManager compared theNoneexpire_timeagainst the current time.What is the new behavior?
It now falls back to a default TTL of 400 days when
cookie.expiresisNone.Does this PR introduce a breaking change?
Other information
Added a regression test that simulates a session cookie with no
Expires/Max-Ageattribute and verifies that authentication succeeds without error.