Skip to content

Harden consent gate lifecycle, timeouts, and fail-open behavior - #75

Open
0x7f wants to merge 9 commits into
mainfrom
fix-further-fixes
Open

0x7f wants to merge 9 commits into
mainfrom
fix-further-fixes

Conversation

@0x7f

@0x7f 0x7f commented Sep 24, 2026

Copy link
Copy Markdown
Member

Summary

  • Fail open (render app content) when CMP/SDK startup, the first-layer WebView, or the CMP second layer stalls or errors, instead of blocking indefinitely.
  • Split the first-layer timeout into a page-load stage and a ready stage so a network/load failure and a stuck init show up distinctly in error reports.
  • Require a valid subscription (not just an authenticated user) to bypass the consent layer.
  • Unregister the SDK state observer on cleanup to prevent stale updates.
  • Harden the Contentpass SDK's lifecycle and network handling: clear the refresh timer on logout/destroy, log out on non-retryable OAuth errors or a missing refresh token, catch init failures instead of leaving an unhandled rejection, and time out hung fetches.
  • Add an optional timeouts prop on ContentpassConsentGate so integrators can override every timeout-driven stage, defaulting to current behavior when omitted.

Test plan

  • Unit tests included for the new/changed behavior (ContentpassConsentGateStartup, Contentpass, fetchWithTimeout, ContentpassSdkProvider)
  • yarn test in CI

@0x7f
0x7f force-pushed the fix-further-fixes branch from 110a9d3 to 40a9c5c Compare September 24, 2026 18:30
Stop blocking app content when CMP or SDK initialization fails or times out.
Render app content when the first layer times out or reports a load error.
Fail open when authentication or the CMP second layer does not complete.
Keep the consent layer active for authenticated users without an active entitlement.
Remove the consent gate observer during cleanup to prevent stale updates.
Clear the refresh timer on logout/destroy, log out when no refresh token
survives a refresh or the token endpoint returns a non-retryable OAuth
error, catch initialisation failures instead of leaving an unhandled
rejection, and add a timeout to the SDK's fetch calls so a hung request
can no longer hang forever.
Fail fast if the static layer HTML never finishes loading, and only start
the full initialization timeout once the page has loaded and is waiting
to report ready. This distinguishes a network/load failure from a stuck
init in error reports, instead of lumping both under one timeout.
Add an optional `timeouts` prop to ContentpassConsentGate covering every
timeout-driven operation (CMP init/metadata/consent-status, Contentpass
authenticate, the CMP second layer, the Contentpass init watchdog, and
the layer's page-load/ready stages), each independently overridable and
defaulting to today's behavior when omitted.
@0x7f
0x7f force-pushed the fix-further-fixes branch from b5e83de to 3f62b57 Compare September 24, 2026 19:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant