Relationships
#3077 Share dashboard authentication across tabs for deep links
Opened by stack72 · 10/6/2026· Shipped 10/6/2026
Observed behavior
Opening a dashboard deep link in a separate browser tab prompts for authentication even while another ops.swamp-club.com dashboard tab remains authenticated.
Example:
https://ops.swamp-club.com/dashboard/workflows/@swamp%2Fci-uat%2Frun/runs/26e54a95-9ce1-4707-822d-aa9d0b9899d4
Reproduction
- Sign in to the Swamp dashboard in one browser tab.
- Keep that authenticated tab open.
- Open a dashboard deep link in a new tab.
- The new tab displays the login flow rather than using the existing authenticated session.
Research
packages/dashboard/src/client/SwampProvider.tsx stores the bearer token under swamp-dashboard-token with sessionStorage (initial read at lines 95–97; writes/removal at lines 125–128 and 226–229). Browser sessionStorage is scoped to an individual top-level browsing context, so a separately opened tab has no token. The same dashboard uses localStorage for preferences, but no cross-tab authentication/session mechanism exists.
This is a cross-tab session-scoping issue rather than evidence that the valid token has expired.
Expected behavior
While an authenticated dashboard session remains valid, opening an ops.swamp-club.com dashboard link in another tab should authenticate that tab without requiring a second login.
Implementation note
Preserve the security properties of the current authentication model: do not blindly broaden bearer-token exposure just to share state. Use a session-sharing approach compatible with the intended threat model, and ensure sign-out/revocation behaves consistently across tabs.
Shipped
Click a lifecycle step above to view its details.
system commented 10/6/2026, 3:18:22 PM
Classified automatically when this issue was filed.
- Source: Swamp Club
If you feel this classification is incorrect, add a ripple to tell us so.
Sign in to post a ripple.