NEC-148: An open vault never re-checks for a pending reset, so Cancel reset may not appear #210

Merged
nectenda-agent merged 3 commits from worktree-nec-148-an-open-vault-never-re-checks-for-a-pend into main 2026-09-29 12:14:35 +01:00
Collaborator

Task: NEC-148 — https://projectron.nerchure.com/tasks/156

An open vault now re-checks for a pending account reset (start over) at least hourly and on window focus, so the Cancel reset notice reaches a device left open for days: the defence CRYPTO-098 relies on against a hijacked mailbox. The check asks /api/me alone. On an expired access token the hourly check rotates only the tokens, through a refresh gate that never hands a full-refresh caller a token-only rotation and never presents one refresh token twice. It does not do the full refresh, which would restart sync. Focus checks never rotate, to limit the lost-reply session risk (server-side fix filed as NEC-152). Two review rounds and two user decisions are recorded in docs/changes/NEC-148-release-recheck/spec.md.

Spec: docs/changes/NEC-148-release-recheck/spec.md

Changelog

A vault left open now notices within the hour, or on returning to the window, when someone asks to reset your account, so you can cancel it.

Task: NEC-148 — https://projectron.nerchure.com/tasks/156 An open vault now re-checks for a pending account reset (start over) at least hourly and on window focus, so the Cancel reset notice reaches a device left open for days: the defence CRYPTO-098 relies on against a hijacked mailbox. The check asks /api/me alone. On an expired access token the hourly check rotates only the tokens, through a refresh gate that never hands a full-refresh caller a token-only rotation and never presents one refresh token twice. It does not do the full refresh, which would restart sync. Focus checks never rotate, to limit the lost-reply session risk (server-side fix filed as NEC-152). Two review rounds and two user decisions are recorded in docs/changes/NEC-148-release-recheck/spec.md. Spec: `docs/changes/NEC-148-release-recheck/spec.md` ## Changelog A vault left open now notices within the hour, or on returning to the window, when someone asks to reset your account, so you can cancel it.
A vault learned of a start-over request only at load or on Refresh, so
one left open for days might never show the notice or Cancel reset, and
that device is the defence CRYPTO-098 relies on. It now asks /api/me
alone an hour after its last ask, and on window focus after five
minutes; a failed check keeps what it had, and one that raced a Cancel
or a full refresh drops its answer.

Task: NEC-148

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01BPaBMartfKcKQbTEDjAYik
The access token lives ten minutes, so almost every check met a 401,
and answering it with the full refresh meant every organisation's
session call and a sync restart each hour and on focus. The check now
rotates the tokens alone through the refresh gate and asks again. The
gate never hands a caller wanting a full refresh a token-only one: it
waits it out and runs its own, so one refresh token is still presented
once.

Also from the review: an open pane redraws when the answer changes,
the throttle stamps every attempt rather than successes only, and the
interval is 55 minutes so a 5-minute tick keeps the wait within the
hour CRYPTO-098 promises.

Task: NEC-148

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Leave token rotation to the timer, and never store an old session's tokens
All checks were successful
Release note / release-note (pull_request) Successful in 13s
CI / build (pull_request) Successful in 4m50s
CI / e2e (pull_request) Successful in 5m22s
CI / promote (pull_request) Has been skipped
9d8883ba47
Every rotation risks the session: a reply lost after the server
committed it leaves the vault holding a retired refresh token, and
presenting that again ends the session. Focus comes up to every five
minutes, often as a laptop wakes, so a focus check now asks with the
token it has and leaves an expired one to the hourly timer. The user
chose this; the server-side grace window is NEC-152.

A token rotation that lands after a sign-out, or a sign-out and a new
sign-in, now drops its result instead of storing a dead session's
tokens over the live one. The e2e pins the stamp where only focus is
due, so the timer cannot pass it by accident.

Task: NEC-148

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
cruelacid force-pushed worktree-nec-148-an-open-vault-never-re-checks-for-a-pend from 9d8883ba47
All checks were successful
Release note / release-note (pull_request) Successful in 13s
CI / build (pull_request) Successful in 4m50s
CI / e2e (pull_request) Successful in 5m22s
CI / promote (pull_request) Has been skipped
to 0c0f2cbb5e
All checks were successful
Release note / release-note (pull_request) Successful in 14s
CI / build (pull_request) Successful in 4m50s
CI / e2e (pull_request) Successful in 5m24s
CI / promote (pull_request) Has been skipped
Deploy site / deploy (push) Successful in 49s
CI / build (push) Successful in 5m9s
CI / e2e (push) Successful in 5m25s
CI / promote (push) Successful in 32s
2026-09-29 12:08:34 +01:00
Compare
Sign in to join this conversation.
No reviewers
No milestone
No project
No assignees
2 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
Nectenda/nectenda!210
No description provided.