Skip to content

fix(anonymous): bump auth0-spa-js to v2.28.2 to properly handle session expiry errors - #1271

Merged
yogeshchoudhary147 merged 1 commit into
mainfrom
fix/bump-auth0-spa-js-2.28.2
Oct 2, 2026
Merged

yogeshchoudhary147 merged 1 commit into
mainfrom
fix/bump-auth0-spa-js-2.28.2

Conversation

@yogeshchoudhary147

@yogeshchoudhary147 yogeshchoudhary147 commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Bumps @auth0/auth0-spa-js to ^2.28.2 to pick up the fix for anonymous session cache cleanup on session expiry (auth0-spa-js#1779)

Test plan

  • npm test passes
  • npm run lint passes

Summary by CodeRabbit

  • Release Notes
    • This update does not change any features, workflows, or behavior visible in the product. No new capabilities, fixes, or interface changes are included. Existing functionality remains available as before, and there are no user-facing changes to highlight in this release.

@yogeshchoudhary147
yogeshchoudhary147 requested a review from a team as a code owner October 2, 2026 12:28
@coderabbitai

coderabbitai Bot commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository: auth0/auth0-react/.coderabbit.yaml

Review profile: CHILL

Plan: Advanced

Run ID: 9ca51945-6e8c-4a87-b8ca-61e36e247bfc

📥 Commits

Reviewing files that changed from the base of the PR and between 525d024 and d06de20.

⛔ Files ignored due to path filters (1)
  • package-lock.json is excluded by !**/package-lock.json
📒 Files selected for processing (1)
  • package.json

Included review availability: This review used your included allowance. Your plan provides up to 4 included reviews per hour; 3 remain after this review.


📝 Walkthrough

Walkthrough

The package manifest updates the required version range for @auth0/auth0-spa-js from ^2.28.1 to ^2.28.2.

Changes

Auth0 SPA dependency update

Layer / File(s) Summary
Update SDK dependency range
package.json
The required @auth0/auth0-spa-js range changes from ^2.28.1 to ^2.28.2.

Priority: ⬇️ Low

Estimated code review effort: 1 (Trivial) | ~5 minutes

Change: Bug fix

Suggested reviewers: gyaneshgouraw

Merge Risk: ⚪ Minimal · up to d06de

This updates the Auth0 SPA SDK to a patch release that fixes cleanup of anonymous sessions on expiry. The manifest and lockfile are consistent, so installs should work. The risk of merging is minimal.

Architecture Summary

Architecture risk: 🔵 Low · up to d06de

The change affects 1 system.

Changed systems: package.json

Architecture concerns
No architecture-level concerns identified.

Review details

Systems and components

  • observed — package.json (service) was modified; 1 changed file maps to changed impact.

Before / after behavior

  • observed — Modified behavior in package.json: The @auth0/auth0-spa-js dependency range changes from ^2.28.1 to ^2.28.2.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly describes the main change: upgrading @auth0/auth0-spa-js to v2.28.2 to address session expiry errors.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.

Warning

Some tools did not complete. Review the errors below.

🔧 ESLint

If the error stems from missing dependencies, add them to the package.json file. For unrecoverable errors (e.g., due to private dependencies), disable the tool in the CodeRabbit configuration.

ESLint install failed: dependency version conflict. Check your lock file or package.json.


Comment @coderabbitai help to get the list of available commands.

@yogeshchoudhary147
yogeshchoudhary147 merged commit 042f55a into main Oct 2, 2026
18 checks passed
@yogeshchoudhary147
yogeshchoudhary147 deleted the fix/bump-auth0-spa-js-2.28.2 branch October 2, 2026 12:36
yogeshchoudhary147 added a commit that referenced this pull request Oct 2, 2026
**Fixed**
- fix(anonymous): bump auth0-spa-js to v2.28.2 to properly handle
session expiry errors
[\#1271](#1271)
([yogeshchoudhary147](https://github.com/yogeshchoudhary147))
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants