fix(auth): one token check for every route — sign-ins last 30 days from login - #183
Merged
Merged
Conversation
…om login Account routes, upload routes and /auth/refresh now resolve access and refresh tokens through one check against the account, and a refresh hands back the refresh token it was sent, so a sign-in lasts 30 days from login. - app/core/tokens.py: access and refresh tokens carry the password-hash fingerprint (phv) that reset links already use; decode_session_token replaces decode_token_full (only tests used it). - app/api/routes/auth.py: _session_user resolves a token to the live account (UUID cast, active, not deleted, matching phv) for get_current_user and /auth/refresh; _token_pair mints the pair for register, login and refresh. /auth/refresh needs a database (503 without one, like login). - Tokens minted before this change have no phv and are refused, so everyone who is signed in signs in once more after the deploy. - Client: app/static/js/auth.js stores the refresh token it gets back, as before; no client change needed. - docs/api-reference.md (refresh and reset rows) and docs/api-usage-guide.md (refresh section, flow diagram) describe the behaviour; tests/test_auth_refresh.py is new. Alternatives considered: a per-user token_version column (a migration, and a bump in every path that should end sessions); server-side refresh-token rotation (a token table plus client changes, since the web UI refreshes from parallel requests with one token). Full suite 1499 green (72 skipped locally); ruff + format + gitleaks clean. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
MrChengLen
force-pushed
the
pr-token-check
branch
from
September 30, 2026 12:55
2af5800 to
3addd4a
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
Account routes, upload routes and
POST /auth/refreshresolve access and refresh tokens through one check against the account (_session_userinapp/api/routes/auth.py). A refresh returns the refresh token it was sent, so a sign-in lasts 30 days from login.app/core/tokens.py: access and refresh tokens carry the password-hash fingerprint (phv) that reset links already use;decode_session_tokenreplacesdecode_token_full.POST /auth/refreshneeds a database (503without one, like login).phvand are refused — everyone who is signed in signs in once more after the deploy.app/static/js/auth.jsstores the refresh token it gets back, as before; no client change.docs/api-reference.md,docs/api-usage-guide.md; CHANGELOG entry.Tests
tests/test_auth_refresh.py; new cases intests/test_password_reset.pyandtests/test_upload_auth_resolution.py; the other token tests passphv.🤖 Generated with Claude Code