Deactivated users keep working until JWT expiry (24h) #34
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Medium
`userService.loginUser` correctly rejects deactivated accounts at login time, but the `authenticate` middleware only verifies the JWT signature — it never rechecks `users.is_active`. After an admin deactivates an account (Admin panel DEL button sets `is_active=false`), the user's existing token keeps full access for up to 24 hours.
`backend/src/middleware/auth.ts` — `authenticate()` decodes and trusts `req.user` with no DB lookup.
Also relevant: JWT claims include `isGM`, so demoting a GM also takes up to 24h to take effect.
Suggested fix
On `authenticate`, cache-and-check the user row (short TTL, e.g. 60s) or at minimum verify `is_active`; optionally bump a `token_version` column embedded in the JWT to invalidate instantly.
✅ Fixed:
authenticatemiddleware now loads fresh account state from DB (60s TTL cache) and rejects deactivated accounts immediatelyemail,isGM), so GM demotion takes effect within ~60s too✅ Fixed & verified live (commit
05b5453):Account deactivated✅Fresh claims also mean GM demotion propagates within the same window. User re-activated after test.