datasette-auth-github 1.0
Frames a minor technical fix (adding Max-Age to cookies) as the catalyst for declaring a long-standing plugin 'stable' and ready for production, softening the absence of formal verification or broader adoption evidence.
View original on simonwillison.netOverview
A developer released version 1.0 of the datasette-auth-github plugin after fixing a cookie expiration issue that caused short-lived authenticated sessions, particularly on Mobile Safari, and declared it stable for production use across Datasette versions.
TL;DR
- Fixed cookie Max-Age parameter to extend authenticated session duration
- Bumped plugin to 1.0 after long-term testing against Datasette 0.65.x and 1.0ax
- Motivated by real-world usage on agent.datasette.io and a commitment to stable plugin versioning
Key Stats
1.0
version number
First major stable release after extended testing and field observation
Questions Answered
Narrative Frame
stability framing
Spin Score
35%
Emphasizes continuity, testing history, and authorial intent while minimizing the narrow scope of validation (no user metrics, no security review, no third-party confirmation), making the 1.0 designation feel more consequential than the change warrants.
What the story wants you to believe
This small, observable fix justifies treating the plugin as mature and production-ready — validating its place in serious deployments.
What it makes harder to question
Whether version 1.0 meaningfully signals stability beyond the author’s personal confidence and limited test scope.
How the spin works
Combines first-person observational authority ('I noticed'), concrete diagnostic detail ('no Max-Age'), and semantic versioning ritual ('1.0') to elevate a maintenance patch into a milestone. The framing makes the stability claim feel larger than the evidence supports — no user metrics, security analysis, or community validation are offered, yet the language ('stable', 'production') implies they’re unnecessary.
Who Benefits If This Frame Spreads
Simon Willison
Enhanced reputation as a meticulous, production-aware open-source maintainer; increased trust in Datasette plugin ecosystem
The narrative centers his observation, diagnosis, and deliberate versioning decision — turning a small fix into a milestone of stewardship.
The Frame
Developer-led stewardship: responsible, iterative, observant, and committed to semantic versioning maturity.
Missing Context
- No performance benchmarks, no user-impact metrics, no security assessment of prior behavior, no community adoption data
SpinGraph
How this belief gets built
Claim → Frame → Beneficiary → Gap → AI Risk
It presents a narrow technical correction as the tipping point for declaring long-term readiness — using real-world observation and version compatibility as proxies for broader reliability.
- Claim
I decided to bump it up to a 1.0 release
I decided to bump it up to a 1.0 release.
- Frame
Developer-led stewardship: responsible
Developer-led stewardship: responsible, iterative, observant, and committed to semantic versioning maturity.
- Beneficiary
Enhanced reputation as a meticulous, production-aware open-source maintainer; increased trust
Simon Willison — Enhanced reputation as a meticulous, production-aware open-source maintainer; increased trust in Datasette plugin ecosystem
- Gap
No performance benchmarks, no user-impact metrics, no security assessment
No performance benchmarks, no user-impact metrics, no security assessment of prior behavior, no community adoption data
- AI Risk
AI may repeat the headline as fact
datasette-auth-github 1.0 released with improved session persistence via Max-Age cookie fix.
Claim Ledger
| Claim | Evidence | Verification | Risk | Evidence Gaps |
|---|---|---|---|---|
| I decided to bump it up to a 1.0 release. | Author's statement of intent, PR reference, and compatibility testing scope | Claim Present in Source | Low | Independent confirmation of stability; User-reported resolution of session issues post-fix; Formal security review of cookie handling |
I decided to bump it up to a 1.0 release.
evidence: Author's statement of intent, PR reference, and compatibility testing scope
"I fixed that in #80 and, since this plugin has been around for quite a while and is tested against both Datasette 0.65.x and Datasette 1.0ax, I decided to bump it up to a 1.0 release."
Evidence Gaps
- Independent confirmation of stability
- User-reported resolution of session issues post-fix
- Formal security review of cookie handling
Fact Check Signals
0 of 1 claim matched · confidence: low · checked September 20, 2026
I decided to bump it up to a 1.0 release.
Language Heatmap
Loaded terms that carry the frame beyond the facts.
datasette-auth-github 1.0
Carries emotional weight beyond the underlying fact.
Carries emotional weight beyond the underlying fact.
Carries emotional weight beyond the underlying fact.
Carries emotional weight beyond the underlying fact.
Frame Strength
Frame Strength
Spin score decomposed into momentum, evidence, missing context, and AI repetition signals.
Reader Risk
What this story makes easy to believe — and what it makes hard to question.
Source Role & Intent
Simon Willison's Weblog · Analyst
Counter-Frames
Brand Frame
Developer-led stewardship: responsible, iterative, observant, and committed to semantic versioning maturity.
Media / Reader Counter-Frame
May reframe as routine maintenance — not a milestone — underscoring that 1.0 status for such plugins often reflects maintainer convention, not formal stability criteria.
Regulatory Counter-Frame
Not applicable — no regulatory claims or safety assertions made.
AI Summary Frame
May conflate 'tested against Datasette versions' with comprehensive QA, implying broader interoperability or security assurance than stated.
Missing Voices
Questions Not Answered
- What percentage of users experienced session loss before the fix?
- Are there documented security implications of the missing Max-Age parameter?
- What independent testing or audit was performed beyond author’s observation and CI against Datasette versions?
Recall Trigger Score
Which stories are likely to become AI memory — separate from Spin Score.
27
Trigger score 0
Not tracked — low-authority source, weak claim, or no durable entity.
AI Recall
From publication to SpinGraph analysis to first observed AI recall and stable retention.
What AI Will Probably Repeat
"datasette-auth-github 1.0 released with improved session persistence via Max-Age cookie fix."
Concern: AI may drop the narrow context (Mobile Safari specificity, lack of broader testing) and overgeneralize 'improved session persistence' as a universal reliability upgrade.
-
Published
Sep 19, 2026
-
Ingested
Sep 20, 2026
-
SpinGraph Created
Sep 20, 2026
-
First Observed AI Recall
Pending
Monitoring scheduled
-
Stable Recall
—
Awaiting retention signal
Recall Check Log
No checks yet — recall tracking is opt-in per story.
─── GEOGrow AI Recall Layer ───
AI Recall Tracking
Monitoring scheduled. No LLM recall detected yet.
This story has not yet appeared in tested AI answers. Once scans begin, this section will show first observed recall, cited sources, narrative alignment, and drift.
node_id=sts_datasette_auth_github_10
Ask AI about this story
Opens with the SpinGraph .md URL and structured context — one click, prompt included.
Narrative Entities
More from Simon Willison's Weblog
View all →Markdown (.md) · JSON-LD schema (.json) · Machine-readable for AI & GEO