Description
Problem
Password UI login and signup create session tokens without ExpiresAt (internal/server/ui_auth_pages.go:40-49, :78-87). The API password session path does the same (internal/server/auth_tokens.go:125-145), as do passkey-created sessions.
AuthenticateToken explicitly accepts a null expiry forever (internal/store/auth.go:76-81). The browser cookie is non-persistent, but the underlying bearer value remains reusable until manual revocation.
Impact
A copied session token survives browser closure and remains valid indefinitely, increasing the account-takeover window for logs, backups, browser compromise, or accidental disclosure.
Acceptance criteria
- Define a configurable server-side absolute session TTL and apply it to every password/passkey UI and API session creation path.
- Align browser cookie expiry/Max-Age with the database expiry.
- Decide and document whether idle expiry is also required.
- Preserve intentionally long-lived API tokens as a distinct, explicit policy.
- Add tests proving expired sessions fail for UI cookies, API bearer auth, and WebSockets.
Sub-issues
0Linked issues
0GitHub
0No branches or pull requests linked.
Comments
0No comments.