JWT refresh endpoint enables permanent token lifetime (no revocation) #38

Closed
opened 2026-08-23 05:42:06 +00:00 by nasandre · 2 comments
Owner

Low

`authController.refresh` accepts any structurally valid token and re-signs it with a fresh 24h expiry — indefinitely, with no rotation, blacklist, or DB state check. A single stolen token can be renewed forever even after password change.

`backend/src/controllers/authController.ts:73-95`

Suggested fix

Short-lived access tokens + refresh-token table (rotation + revoke on password change/logout), or at least refuse refresh for tokens older than N days and validate current `is_active`/`is_gm` from DB when re-signing.

## Low \`authController.refresh\` accepts any structurally valid token and re-signs it with a fresh 24h expiry — indefinitely, with no rotation, blacklist, or DB state check. A single stolen token can be renewed forever even after password change. \`backend/src/controllers/authController.ts:73-95\` ## Suggested fix Short-lived access tokens + refresh-token table (rotation + revoke on password change/logout), or at least refuse refresh for tokens older than N days and validate current \`is_active\`/\`is_gm\` from DB when re-signing.
Author
Owner

✅ Fixed:

  • Refresh refuses tokens older than 7 days (iat check) — stolen tokens can't be renewed forever
  • Re-signs with CURRENT account state fetched from DB; deactivated/missing accounts get 403
✅ **Fixed**: - Refresh refuses tokens older than 7 days (`iat` check) — stolen tokens can't be renewed forever - Re-signs with CURRENT account state fetched from DB; deactivated/missing accounts get 403
Author
Owner

✅ Fixed (commit 05b5453) — refresh now: refuses tokens older than 7 days (iat check), re-signs from CURRENT DB state, and returns 403 for deactivated/missing accounts. Combined with #34's middleware change, stolen-token value decays to zero within a week max.

✅ **Fixed** (commit `05b5453`) — refresh now: refuses tokens older than 7 days (iat check), re-signs from CURRENT DB state, and returns 403 for deactivated/missing accounts. Combined with #34's middleware change, stolen-token value decays to zero within a week max.
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
nasandre/wh40-rogue-trader#38
No description provided.