NEC-152: A refresh reply lost to the network signs the vault out: no grace window for the rotated-out token #211
No reviewers
Labels
No labels
area:docs
area:identity
area:ops
area:plugin
area:server
channel:community
channel:direct
channel:owned
channel:press
channel:social
e2ee-constrained
gate:at-ga
gate:pre-ga
marketing
parity
relay:absent
relay:planned
relay:requested
relay:supported
risk:additive
risk:contract
risk:none
usability
No milestone
No project
No assignees
2 participants
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
Nectenda/nectenda!211
Loading…
Reference in a new issue
No description provided.
Delete branch "worktree-nec-152-a-refresh-reply-lost-to-the-network-sign"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Task: NEC-152 — https://projectron.nerchure.com/tasks/160
A refresh whose reply is lost to the network no longer signs the vault out. For 10 minutes after a rotation (REFRESH_GRACE_SECONDS), the rotated-out token is answered with a new one when it comes from the session's own install id. So that a stolen token stays detectable, every displaced token hash is now kept for 30 days (RETIRED_REFRESH_TOKEN_DAYS, pruned hourly and when the session ends), and its return revokes the session. This also closes an older gap on main, where refreshing a stolen token twice pushed the owner out silently. The reuse log now dates a retired token's return correctly and marks it retired: true. Ride-along NEC-153: a sign-out with a pushed-out token now ends the session. Two fresh-context reviews shaped this; the retention and table design were the user's decisions.
Spec:
docs/changes/NEC-152-refresh-grace-window/spec.mdAlso fixes NEC-153: Signing out with a refresh token two rotations back revokes nothing
Changelog
Losing the network in the middle of a sign-in refresh no longer signs your vault out.
42faac7252f73afaa09d