Repository navigation
Expire a batch action's proxy token no later than upstream's href [patch] - #108
Merged
Merged
Conversation
…tch] BatchRewriter gave every action the proxy's TokenLifetime (1h by default), removed upstream's expires_at and overwrote expires_in. The token still carries upstream's href and header, which for GitHub LFS and pre-signed S3/Azure URLs often last 5-15 minutes. A client told the action was valid for an hour never re-batched, and a fetch of an uncached object after upstream's expiry was relayed as 401/403. Each action's expiry is now the earliest of the proxy lifetime and upstream's expires_at and now + expires_in, with upstream's brought forward by a 30-second margin so a transfer that starts just inside the window still reaches upstream in time. That one value is both the token's ExpiresAt and the advertised expires_in. An action with no upstream expiry, or one later than the proxy lifetime, keeps TokenLifetime. An expiry of the wrong type is ignored. Fixes #66 Co-Authored-By: Claude Opus 5.5 <[email protected]> Claude-Session: https://claude.ai/code/session_01WY7QGzbH6kE2oceF1hP8fh
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



Fixes #66
What was wrong
BatchRewritercomputed a singlenow + TokenLifetime(1h by default) for the whole response. For every action it removed upstream'sexpires_atand overwroteexpires_inwith that lifetime. The token still carries upstream'shrefandheader, and for GitHub LFS and pre-signed S3/Azure URLs those often last only 5 to 15 minutes. git-lfs had been told the action was good for an hour, so it never re-batched. A fetch of an uncached object after upstream's expiry was then relayed to it as a 401 or 403.Change
expires_at;now + expires_in.BatchRewriter.UpstreamExpiryMargin), so a transfer that starts just inside the advertised window still reaches upstream before the credential lapses. The triage note asked for this margin.ExpiresAtand the advertisedexpires_in, so the two can't disagree.expires_atis still removed, andexpires_innever goes below 0.TokenLifetimeexactly as before.expires_at/expires_inof the wrong JSON type, or one that can't be parsed, is ignored rather than throwing. A hugeexpires_inis clamped so the date arithmetic can't overflow.expires_infrom the token lifetime" and the README'sTokenLifetimerow now say "never later than upstream", as the issue asked.Tests
In
BatchRewriterTests:Rewrite_UpstreamExpiresSooner_TokenAndExpiresInFollowUpstreamcoversexpires_in: 600,expires_at10 minutes out, and both together in either order. Each case checks thatexpires_inis 570, that the token'sExpiresAtisnow + 570s, and that the token is refused once the clock reaches 600 s.Rewrite_UpstreamExpiresLater_KeepsTheTokenLifetimeandRewrite_ActionWithNoUpstreamExpiry_KeepsTheTokenLifetimecheck that 3600 is kept.Rewrite_UnusableUpstreamExpiry_IsIgnoredcovers a stringexpires_in, a numeric or unparseableexpires_at, andlong.MaxValue.Rewrite_UpstreamAlreadyExpired_AdvertisesZero.expires_atis exactly one hour out, so with the margin its token now expires 30 s sooner.Rewrite_SetsExpiresInFromTokenLifetimeAndDropsExpiresAtis split so the lifetime case uses an action with no upstream expiry.With the fix reverted, 6 cases fail (the four upstream-sooner rows, the already-expired case and the updated ADO assertion). The full suite passes locally: 365 tests, 0 failed.
BatchRewriter.csis also touched by #104. This change is placed so the two don't overlap, and the branch merges cleanly with #101, #102, #103, #104 and #107.🤖 Generated with Claude Code
https://claude.ai/code/session_01WY7QGzbH6kE2oceF1hP8fh
Generated by Claude Code