Skip to content

Force-revoke can strand a suite migration that is still in progress #803

Description

@rjzondervan

Code reading on 28 September 2026 at 124849b (development). Unverified: not checked live. Found in the development → beta security review. This is new in the delta: the route does not exist on beta.

What happens

POST /api/v1/suites/{id}/force-revoke (EncryptionSuiteController::forceRevoke, about line 436, then EncryptionSuiteService::revokeSuite()) does not check whether the suite is the old or new end of a migration that is still in_progress.

  • Revoking the old suite blocks the reads the owner's browser needs in order to re-encrypt, so the migration cannot finish.
  • Revoking the successor makes records that were already re-encrypted, or are being written, unreadable.

Either way, the migration and the vault write lock stay in_progress. Only an admin can do this, so it is an operator error rather than an attack, but the result is a user stuck mid-rotation.

Proposed fix

Refuse a force-revoke while the suite is part of an in-progress migration, with a clear message that points to aborting or completing the migration first. Alternatively, require an explicit acknowledgement and abort the migration as part of the revoke.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

bugSomething isn't workingencryption-suitesEncryptionSuite lifecycletriageAwaiting triage

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions