JWT refresh endpoint enables permanent token lifetime (no revocation) #38
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Low
`authController.refresh` accepts any structurally valid token and re-signs it with a fresh 24h expiry — indefinitely, with no rotation, blacklist, or DB state check. A single stolen token can be renewed forever even after password change.
`backend/src/controllers/authController.ts:73-95`
Suggested fix
Short-lived access tokens + refresh-token table (rotation + revoke on password change/logout), or at least refuse refresh for tokens older than N days and validate current `is_active`/`is_gm` from DB when re-signing.
✅ Fixed:
iatcheck) — stolen tokens can't be renewed forever✅ Fixed (commit
05b5453) — refresh now: refuses tokens older than 7 days (iat check), re-signs from CURRENT DB state, and returns 403 for deactivated/missing accounts. Combined with #34's middleware change, stolen-token value decays to zero within a week max.