Repository navigation
Retire access tokens leaked before the server:clients fix (GRYT-1259) - #195
Merged
Merged
Conversation
Before GRYT-1239, every member's live access token reached every other member through server:clients, and a token that leaked can't be recalled. This bumps server_config.token_version once, on the upgrade that carries the fix, so every access token minted before it stops passing requireAuth and token:refresh. It runs as a schema_meta-marked one-shot in runMigrations, so it fires once and never again. It skips a database nobody has joined, since a fresh install never issued a token to leak, and still writes the marker there so a later boot never reconsiders. One log line when it fires. Refresh tokens are untouched, so a live client falls back to its refresh token and re-mints at the new version on its own. Only a captured access token stops working. Verified on a throwaway server: joined on the old code, captured the token, restarted onto this branch. The migration bumped the counter and logged once, the old token was refused at requireAuth and token:refresh, the refresh token minted a new one, and the new one restored the session. A second restart did not bump again. Co-Authored-By: Claude Opus 5 <[email protected]>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Review-required path
This adds a migration under
packages/server/src/db/**(persistence), so it needs a read of the whole diff before it merges. The changed files are the newtokenReissueMigration.ts, its test, and one call plus one import wired intoconnection.ts.Why
server#194 (GRYT-1239) stops
server:clientsandserver:details.clientsfrom leaking every member's live access token, but it cannot recall a token that already leaked. While the bug was live an attacker could roll a captured access token forward indefinitely by refreshing inside each fifteen-minute window, so an upgrade that only stops new leaks still leaves the captured ones working.What it does
reissueAccessTokensAfterLeakbumpsserver_config.token_versionby one, once, insiderunMigrations. That counter is whatrequireAuth, session restore andtoken:refreshcompare a token against, so every access token minted before the bump is refused from then on.schema_metamarker (access_token_reissue_gryt1239) records that it ran, in the same transaction as the bump, so a later boot never repeats it.server_config. A live client whose access token is now refused falls back to its refresh token and re-mints at the new version on its own, so the sign-out is a brief reconnect rather than a re-login. Refresh tokens were never exposed by the leak.Tests
tokenReissueMigration.test.ts:requireAuthand attoken:refreshafterwards;Verified end to end on a throwaway server: joined on
origin/main(the code before this migration), captured the access and refresh tokens, then restarted onto this branch against the same data directory. The migration bumpedtoken_version0 to 1 and logged one line; the captured access token came backtoken:revoked(token_version_mismatch) and got no session; the refresh token minted a fresh access token; the fresh token restored the session. A second restart did not bump again.Local CI:
yarn test(1336),yarn test:examples(9),npx tsc --noEmit,yarn build,npx eslint .,node scripts/check-comment-length.mjs, all clean.Release
This is the recall half of the
server:clientsfix. It should ship together with server#194 (GRYT-1239), and with #192 (GRYT-1238) and #193 already onmain.🤖 Generated with Claude Code