# Strengthening session security across three repositories. One Deployment.io Task coordinated a session-security update across our shared library, API, and dashboard, followed by engineer review and a staged production rollout. - Type: Case study of Deployment.io's work on its own product - Area: Security and compliance remediation (https://deployment.io/solutions/security-compliance/) - When: September 2026 ## Results - **3** — repositories changed by one Task - **22 min** — from Task start to three pull requests - **4** — issues caught in engineer review before merge ## The situation We needed to strengthen session handling across the dashboard and API while keeping existing sessions working during the transition. The work touched a shared Go library, the API, and the React dashboard. It required a coordinated rollout in dependency order: library, then API, then dashboard. ## What Deployment.io did We added a one-page brief to a Deployment.io Assistant session connected to all three repositories. The session produced a specification with the design and merge order. A Task created from that specification opened three pull requests 22 minutes after starting. - Shared library: added consistent session-refresh settings and rollout telemetry. - API: added session refresh and sign-out paths with request-origin checks and support for a staged rollout. - Dashboard: coordinated session refresh, migrated existing sessions, and updated authentication for live streams. Builds and tests passed in all three repositories before the pull requests opened, including 26 new dashboard tests. The handoff included browser verification as a separate acceptance step. ## Engineer review and production rollout Engineer review resolved four issues before merge, covering migration cleanup, recovery after failed session checks, token refresh, and decoding compatibility. All three pull requests merged in dependency order within two hours of each other. The changes were deployed on 16 September 2026. Production browser checks covered page reloads, existing-session migration, deep links, and live Assistant messages. A live-stream regression found after deployment was fixed in a follow-up release, with tests added to cover it. The 22-minute figure measures Task start to the three initial pull requests. It excludes specification, engineer review, production rollout, and the follow-up correction. ## The work - **Repositories changed:** Shared Go library, API, dashboard - **Initial pull requests:** 37 files across 3 repositories - **Verification:** Builds and tests in all three repositories, 26 new dashboard tests - **Engineer review:** 4 issues fixed before merge - **Production rollout:** 16 September 2026, including a follow-up stream correction ## About - **Company:** Deployment.io - **Cloud:** AWS - **Stack:** Go services and a React dashboard in separate repositories --- Source: https://deployment.io/case-studies/session-security-across-three-repositories/