Skip to content

fix(auth): one token check for every route — sign-ins last 30 days from login - #183

Merged
MrChengLen merged 1 commit into
mainfrom
pr-token-check
Sep 30, 2026
Merged

MrChengLen merged 1 commit into
mainfrom
pr-token-check

Conversation

@MrChengLen

Copy link
Copy Markdown
Owner

What

Account routes, upload routes and POST /auth/refresh resolve access and refresh tokens through one check against the account (_session_user in app/api/routes/auth.py). A refresh returns the refresh token it was sent, so a sign-in lasts 30 days from login.

  • app/core/tokens.py: access and refresh tokens carry the password-hash fingerprint (phv) that reset links already use; decode_session_token replaces decode_token_full.
  • POST /auth/refresh needs a database (503 without one, like login).
  • Tokens minted before this change have no phv and are refused — everyone who is signed in signs in once more after the deploy.
  • app/static/js/auth.js stores the refresh token it gets back, as before; no client change.
  • Docs: docs/api-reference.md, docs/api-usage-guide.md; CHANGELOG entry.

Tests

  • New tests/test_auth_refresh.py; new cases in tests/test_password_reset.py and tests/test_upload_auth_resolution.py; the other token tests pass phv.
  • Local: full suite 1492 passed (72 skipped on Windows); ruff + format clean; gitleaks and scope guard clean.

🤖 Generated with Claude Code

…om login

Account routes, upload routes and /auth/refresh now resolve access and
refresh tokens through one check against the account, and a refresh hands
back the refresh token it was sent, so a sign-in lasts 30 days from login.

- app/core/tokens.py: access and refresh tokens carry the password-hash
  fingerprint (phv) that reset links already use; decode_session_token
  replaces decode_token_full (only tests used it).
- app/api/routes/auth.py: _session_user resolves a token to the live
  account (UUID cast, active, not deleted, matching phv) for
  get_current_user and /auth/refresh; _token_pair mints the pair for
  register, login and refresh. /auth/refresh needs a database (503
  without one, like login).
- Tokens minted before this change have no phv and are refused, so
  everyone who is signed in signs in once more after the deploy.
- Client: app/static/js/auth.js stores the refresh token it gets back,
  as before; no client change needed.
- docs/api-reference.md (refresh and reset rows) and
  docs/api-usage-guide.md (refresh section, flow diagram) describe the
  behaviour; tests/test_auth_refresh.py is new.

Alternatives considered: a per-user token_version column (a migration,
and a bump in every path that should end sessions); server-side
refresh-token rotation (a token table plus client changes, since the web
UI refreshes from parallel requests with one token).

Full suite 1499 green (72 skipped locally); ruff + format + gitleaks clean.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@MrChengLen
MrChengLen merged commit b2deb14 into main Sep 30, 2026
7 checks passed
@MrChengLen
MrChengLen deleted the pr-token-check branch September 30, 2026 13:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant