fix(auth): bind request auth snapshots

This commit is contained in:
2026-08-17 01:11:25 +02:00
parent 94c2cd3709
commit 09e546c1ef
8 changed files with 308 additions and 58 deletions
+8 -4
View File
@@ -105,7 +105,7 @@ export interface AuthSessionValidity {
export interface AuthSessionStore {
create(input: SessionCreateInput, now?: Date): Promise<CreatedAuthSession>;
resolve(token: string, now?: Date): Promise<AuthSessionRecord | undefined>;
resolve(token: string, now?: Date, validity?: AuthSessionValidity): Promise<AuthSessionRecord | undefined>;
touch(token: string, now?: Date): Promise<void>;
revoke(token: string): Promise<void>;
prune(now?: Date): Promise<number>;
@@ -801,7 +801,11 @@ export function createFileAuthSessionStore(
throw invalid();
}
async function resolveSession(token: string, now = new Date()): Promise<AuthSessionRecord | undefined> {
async function resolveSession(
token: string,
now = new Date(),
requestValidity = validity,
): Promise<AuthSessionRecord | undefined> {
if (!canonicalRawValue(token)) return undefined;
const nowMs = dateMilliseconds(now);
const filename = digestFilename(token);
@@ -816,7 +820,7 @@ export function createFileAuthSessionStore(
return undefined;
}
try {
if (await recordIsCurrent(record, validity)) return record;
if (await recordIsCurrent(record, requestValidity)) return record;
} catch (error) {
if (error instanceof AuthSessionOperationalError) throw error;
await bridge.remove(root, "sessions", filename);
@@ -833,7 +837,7 @@ export function createFileAuthSessionStore(
return undefined;
}
try {
if (await recordIsCurrent(trusted.value, validity)) return trusted.value;
if (await recordIsCurrent(trusted.value, requestValidity)) return trusted.value;
} catch (error) {
if (error instanceof AuthSessionOperationalError) throw error;
removeTrusted(directories.sessions, filename, trusted.identity);