trackslash
TRACK-59 P3

Auto-revoke web sessions older than 3 years via a Postgres cleanup job

0
All issues

Description

Web session tokens accumulate indefinitely. They should age out automatically instead of relying on manual revocation.

Proposed behaviour

Session tokens older than 3 years are auto-revoked. The cleanup runs inside Postgres, triggered on user token refresh, so there is no external scheduler or cron dependency.

Design notes

  • Trigger point: the token-refresh path. Each refresh is a natural, already-happening write, so it amortises the cleanup across normal traffic.
  • Scope the sweep to session tokens only — API tokens are long-lived by design and must not be swept.
  • Age is measured from token creation.
  • Guard against doing the sweep on every single refresh; a busy instance would run it constantly. Rate-limit it (e.g. only sweep when the last sweep was over N hours ago, tracked in a small table row) or bound each sweep to a fixed row limit so the refresh path stays fast.
  • The sweep must not delete the token currently being refreshed.
  • Per CLAUDE.md, this goes in a goose migration with +goose StatementBegin/End markers per logical block.

Tests

Integration tests for: a 3-year-old session token is revoked on refresh; a fresh session token is not; an old API token is not; the refreshing token itself survives; the rate limit prevents a second immediate sweep.

Related

Pairs with the tokens-page grouping ticket — fewer stale sessions makes the grouped count meaningful.

Sub-issues

0

Linked issues

0

GitHub

0

No branches or pull requests linked.

Comments

0
No comments.