Code reading on 28 September 2026 at 124849b (development). Unverified: not checked live. Found in the development → beta security review. This is new in the delta: the route does not exist on beta.
What happens
POST /api/v1/suites/{id}/force-revoke (EncryptionSuiteController::forceRevoke, about line 436, then EncryptionSuiteService::revokeSuite()) does not check whether the suite is the old or new end of a migration that is still in_progress.
- Revoking the old suite blocks the reads the owner's browser needs in order to re-encrypt, so the migration cannot finish.
- Revoking the successor makes records that were already re-encrypted, or are being written, unreadable.
Either way, the migration and the vault write lock stay in_progress. Only an admin can do this, so it is an operator error rather than an attack, but the result is a user stuck mid-rotation.
Proposed fix
Refuse a force-revoke while the suite is part of an in-progress migration, with a clear message that points to aborting or completing the migration first. Alternatively, require an explicit acknowledgement and abort the migration as part of the revoke.
Code reading on 28 September 2026 at 124849b (development). Unverified: not checked live. Found in the development → beta security review. This is new in the delta: the route does not exist on beta.
What happens
POST /api/v1/suites/{id}/force-revoke(EncryptionSuiteController::forceRevoke, about line 436, thenEncryptionSuiteService::revokeSuite()) does not check whether the suite is the old or new end of a migration that is stillin_progress.Either way, the migration and the vault write lock stay
in_progress. Only an admin can do this, so it is an operator error rather than an attack, but the result is a user stuck mid-rotation.Proposed fix
Refuse a force-revoke while the suite is part of an in-progress migration, with a clear message that points to aborting or completing the migration first. Alternatively, require an explicit acknowledgement and abort the migration as part of the revoke.