docs(quick-260927-q23): fix CR-01: /auth/refresh must enforce tokens_valid_after and is_activated

This commit is contained in:
Jakub Zych
2026-09-27 19:12:05 +02:00
parent a13a1214cb
commit a405b1b7ff
5 changed files with 433 additions and 3 deletions

View File

@@ -8,7 +8,7 @@ created: 2026-09-27T16:36:06Z
| Finding | Severity | Disposition | Note |
|---|---|---|---|
| CR-01 | critical | open | Refresh ignores the tokens_valid_after cutoff, so the SPA undoes session revocation (confirmed in bouncer/refresh.go; flaw from 09-01, exposed by the Phase 10 cookie auto-refresh) |
| CR-01 | critical | fixed | Fixed in be4a923 (tests a13a121), quick 260927-q23. Admin refresh now applies the backend guard's subject checks (activated, not deleted, iat not before tokens_valid_after) via bouncer.RefreshAudienceFor before minting, and a refused cookie refresh expires summer_admin. |
| WR-01 | warning | open | Logout does not expire the cookie when the token is rejected |
| WR-02 | warning | open | A belongsTo foreign key exposed as a scalar field skips the relation scope check |
| WR-03 | warning | open | Model rules run before relation values are assigned |