alpha
Login
or
Join now
mihaizaurus.at
/
tranquil-pds
Star
0
Fork
0
Atom
Configure Feed
Issues
Pull Requests
Commits
Tags
Feed URL
Select the types of activity you want to include in your feed.
Our Personal Data Server from scratch!
Star
0
Fork
0
Atom
Configure Feed
Issues
Pull Requests
Commits
Tags
Feed URL
Select the types of activity you want to include in your feed.
Overview
Issues
Pulls
Pipelines
tranquil-pds
/
crates
/
tranquil-auth
/
src
/
at
main
5 files
Lewis
auth: typed TokenVerifyError from es256k verifier
2mo ago
1411506d
lib.rs
auth: typed TokenVerifyError from es256k verifier Lewis: May this revision serve well! <lu5a@proton.me>
2 months ago
token.rs
bsky(auth): add grace period to legacy session refresh Concurrent or retried com.atproto.server.refreshSession calls presenting the same refresh token hit the reuse-detection path, which deleted the session and returned "Refresh token has been revoked due to suspected compromise" — logging users out at random. The legacy flow had no grace period, unlike OAuth. Mirror the reference atproto PDS: every rotated refresh token gets a 2h grace window measured from its own rotation time (used_refresh_tokens.used_at in postgres; a rotated_at_ms field appended to the metastore used-marker, with old-format markers decoding as outside the window). A refresh presenting a recently-rotated token is served the session's current tokens, re-minted on the fly with the same jti/expiry — signed JWTs are never persisted. Reuse outside the window still revokes the session. The grace lookup returns the session's encrypted signing key so the handler verifies the presented token's signature before minting replacement tokens or revoking a session; a forged token bearing a known jti gets a generic rejection with no side effects. Integration tests asserting the old replay-gets-401 behavior are reworked to the new contract and now also cover forged-signature replays and out-of-window revocation.
3 months ago
totp.rs
fix: bulk type safety improvements, added a couple of tests
7 months ago
types.rs
chore(auth): also mention that atproto spec requiers typ be "JWT" for inter-service tokens
3 months ago
verify.rs
auth: typed TokenVerifyError from es256k verifier Lewis: May this revision serve well! <lu5a@proton.me>
2 months ago