docs(quick-260927-q23): fix CR-01: /auth/refresh must enforce tokens_valid_after and is_activated
This commit is contained in:
@@ -8,7 +8,7 @@ created: 2026-09-27T16:36:06Z
|
||||
|
||||
| Finding | Severity | Disposition | Note |
|
||||
|---|---|---|---|
|
||||
| CR-01 | critical | open | Refresh ignores the tokens_valid_after cutoff, so the SPA undoes session revocation (confirmed in bouncer/refresh.go; flaw from 09-01, exposed by the Phase 10 cookie auto-refresh) |
|
||||
| CR-01 | critical | fixed | Fixed in be4a923 (tests a13a121), quick 260927-q23. Admin refresh now applies the backend guard's subject checks (activated, not deleted, iat not before tokens_valid_after) via bouncer.RefreshAudienceFor before minting, and a refused cookie refresh expires summer_admin. |
|
||||
| WR-01 | warning | open | Logout does not expire the cookie when the token is rejected |
|
||||
| WR-02 | warning | open | A belongsTo foreign key exposed as a scalar field skips the relation scope check |
|
||||
| WR-03 | warning | open | Model rules run before relation values are assigned |
|
||||
|
||||
Reference in New Issue
Block a user