From cb1bc6ab62552f271ff4aa9a7123809c9281e4e3 Mon Sep 17 00:00:00 2001 From: zZebrahz Date: Sat, 30 May 2026 21:39:10 -0700 Subject: [PATCH] fix(auth): preserve profile tokens on library changes --- internal/auth/repository.go | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/internal/auth/repository.go b/internal/auth/repository.go index 7c29579c..2ddf4a07 100644 --- a/internal/auth/repository.go +++ b/internal/auth/repository.go @@ -273,7 +273,8 @@ func (r *UserRepository) Update(ctx context.Context, id int, input models.Update } if input.LibraryIDs != nil { setClauses = append(setClauses, fmt.Sprintf("library_ids = $%d", argIndex)) - accessPolicyPredicates = append(accessPolicyPredicates, fmt.Sprintf("library_ids IS DISTINCT FROM $%d", argIndex)) + // Library scope is resolved from users.library_ids on each request, so + // changing it must not invalidate durable profile/session tokens. args = append(args, *input.LibraryIDs) argIndex++ }