fix(gallery): clear the guest identity on gallery logout
The gallery password is one shared secret per event and does not distinguish people. With the guest identity outliving the tab, logging out and letting the next person enter that password greeted them by the previous guest's name, with "forget me" - which erases that guest's selections server-side - one click away. Logout is the leaving-this-device signal, so it now drops the local identity too. Server row untouched.
This commit is contained in:
@@ -11,6 +11,7 @@ import {
|
||||
setActiveGallerySlug,
|
||||
storeGalleryToken,
|
||||
} from '../utils/galleryAuthStorage';
|
||||
import { clearGuestIdentity } from '../utils/guestIdentityStorage';
|
||||
import type { GalleryAccessLevel } from '../types';
|
||||
|
||||
interface GalleryEvent {
|
||||
@@ -350,6 +351,12 @@ export const GalleryAuthProvider: React.FC<GalleryAuthProviderProps> = ({ childr
|
||||
sessionStorage.removeItem(`gallery_event_${currentSlug}`);
|
||||
sessionStorage.removeItem(`gallery_access_level_${currentSlug}`);
|
||||
clearGalleryToken(currentSlug);
|
||||
// Logout is the "I am leaving this device" signal. Now that the guest
|
||||
// identity outlives the tab (#1265), leaving it behind would greet the
|
||||
// next person who enters the shared gallery password by this guest's
|
||||
// name — with "forget me", which erases THIS guest's selections
|
||||
// server-side, one click away. Local only; the server row is untouched.
|
||||
clearGuestIdentity(currentSlug);
|
||||
}
|
||||
authService.galleryLogout(currentSlug || undefined);
|
||||
setIsAuthenticated(false);
|
||||
|
||||
Reference in New Issue
Block a user