Session / district correctness
- public/index.php: add a /?logout=1 endpoint that destroys the PWA's own PHP
session (session_destroy + expire PHPSESSID + clear sso_auth_token, then
redirect to the SSO portal). Logout previously cleared only the SSO cookie,
leaving the PHPSESSID session — and its frozen district_id — intact, which is
why a reassigned user kept loading the old district across logout/login.
- SSO token is validated once per session, at login (unchanged first-login
logic). A district transfer is now picked up on the next logout→login, which
is correct precisely because logout finally tears the session down. No
periodic SSO polling.
- main.js: the menu Logout button routes through /?logout=1 and wipes
district-scoped local caches first. Logout is blocked while offline — a
session can only be created online, so an offline logout would strand the
user with no way back in (and would not actually reach the server).
- main.js: enforceDistrictConsistency() clears district-scoped caches when the
session district changes between loads; the district boundary is cached under
a per-district key (district_boundary_<id>) so one district's geometry can
never be served for another.
GPS coordinate format
- New "GPS Coordinate Format" setting (Lat/Lon · UTM · Both) in the Settings
panel; the navbar read-out renders the chosen format and repaints the current
fix immediately on change. Self-contained WGS84→UTM converter in
geo-utils.js, verified against an independent Redfearn-series implementation.
ol-ext touch cursor
- MapView gates the TouchCursor to genuine touch-only devices via matchMedia
(any-pointer: fine / any-hover: hover); hybrid touchscreen laptops keep the
normal cursor. Reactive to pointer-capability changes.
- Service worker v11 → v12 (new shell). docs/SSO_Session_Refresh_Proposal.md
documents the implemented approach.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>