Tensor
The Agentic Development Environment for the Ambitious
Join waitlistTensor
Workspaces
Bola Banjo
Refactor the auth middleware — split session parsing, refresh rotation, and redirect handling into isolated, testable units.
Worked for 2m 41s
I'll split the auth middleware into focused units, keeping every existing redirect contract intact. Starting with a full read of the current flow so nothing subtle gets lost in the split.
Session parsing, refresh rotation, and redirects are tangled in one module — separating them now. Each unit gets a narrow boundary so failures stay isolated and tests can target them directly.
Units are split — verifying with tests and type checks before I hand it back. I'll run the auth suite plus a full type check, then confirm the legacy callback URLs still resolve.
Done — lib/tensor-auth.ts is now three focused units with the existing redirect contracts untouched. Refresh rotation got its own retry boundary, so a failed rotation no longer takes down session parsing.
The refactor
Session parsing, rotation (rotate-refresh), and redirects (resolve-redirect) are independently testable — 14 new cases cover expired sessions, concurrent refreshes, and legacy callback URLs that must keep working.