Description
Web session tokens accumulate indefinitely. They should age out automatically instead of relying on manual revocation.
Proposed behaviour
Session tokens older than 3 years are auto-revoked. The cleanup runs inside Postgres, triggered on user token refresh, so there is no external scheduler or cron dependency.
Design notes
- Trigger point: the token-refresh path. Each refresh is a natural, already-happening write, so it amortises the cleanup across normal traffic.
- Scope the sweep to session tokens only — API tokens are long-lived by design and must not be swept.
- Age is measured from token creation.
- Guard against doing the sweep on every single refresh; a busy instance would run it constantly. Rate-limit it (e.g. only sweep when the last sweep was over N hours ago, tracked in a small table row) or bound each sweep to a fixed row limit so the refresh path stays fast.
- The sweep must not delete the token currently being refreshed.
- Per
CLAUDE.md, this goes in a goose migration with+goose StatementBegin/Endmarkers per logical block.
Tests
Integration tests for: a 3-year-old session token is revoked on refresh; a fresh session token is not; an old API token is not; the refreshing token itself survives; the rate limit prevents a second immediate sweep.
Related
Pairs with the tokens-page grouping ticket — fewer stale sessions makes the grouped count meaningful.
Sub-issues
0Linked issues
0GitHub
0No branches or pull requests linked.
Comments
0No comments.