Check socket.assigns.current_scope (validated by mount_current_scope) instead of raw session token. Prevents stale/invalid session cookies from bypassing the site-live gate. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| cart_test.exs | ||
| collection_test.exs | ||
| coming_soon_test.exs | ||
| content_test.exs | ||
| home_test.exs | ||
| product_show_test.exs | ||