[T3 Connect] Stop re-signed websocket tokens from outliving the original - #6022
Draft
bradleyshep wants to merge 1 commit into
Draft
bradleyshep wants to merge 1 commit into
bradleyshep wants to merge 1 commit into
Conversation
bradleyshep
force-pushed
the
bradley/websocket-token-lifetime
branch
2 times, most recently
from
September 30, 2026 17:45
2b5439d to
5a914a6
Compare
/v1/identity/websocket-token re-signed any token it accepted, its own included, with a fresh iat and an exp 60 s out. Re-signing each copy before it expired renewed a token forever, and modules could never tell when a session token was issued. The copy now keeps the original iat and expires within 60 s but never after the original.
bradleyshep
force-pushed
the
bradley/websocket-token-lifetime
branch
from
October 1, 2026 17:26
5a914a6 to
4c9d3f9
Compare
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description of Changes
/v1/identity/websocket-tokenre-signed any token it accepted, including its own copies, with a freshiatand anexp60 s out. So re-signing each copy before it expired renewed a token forever, and a module could never tell when the underlying session token was actually issued (for example, to refuse tokens older than a couple of minutes).The re-signed copy now keeps the original
iatand expires within 60 s, but never after the original token'sexp. A token with noexpstill gets one 60 s out.This came out of #6006; it wasn't carried into the split PRs (#6009–#6013) because it's a server behaviour change rather than an SDK fix.
API and ABI breaking changes
None to the API. Two behaviour changes:
iatinstead of the re-sign time. That applies to every connection the TypeScript SDK makes with a token (it always swaps the token through this endpoint, in browsers and Node), and to the Rust SDK'sbrowserbuild and C#'s WebGL build.Rollback safety impact
n/a
Expected complexity level and risk
iat/expthe re-signed claims carry.Testing
re_sign_never_extends_a_token: a token expiring in 30 s re-signs to a copy with the sameiatandexp(the old code gave it a fresh 60 s); a token with no expiry gets one within 60 s (allowing JWT whole-second rounding); re-signing that copy again keeps itsiatandexpinstead of renewing itcargo test -p spacetimedb-client-api --lib auth(7 passing, five runs in a row)rustfmt --check