mirror of
https://github.com/AletheiaVox/signal_bridge_remote.git
synced 2026-10-07 11:28:16 +08:00
fix(security): require auth on every MCP request; stop stale refreshes banning clients
- Remove the authless "sole connected phone" fallback and SB_REQUIRE_MCP_AUTH: an unauthenticated request no longer reaches whichever phone is online alone. - Mcp-Session-Id is no longer a credential; the Bearer token is checked on every request (MCP auth spec). - Refresh tokens live 90 days (was 30, equal to the access token, so they were always dead when first needed). - A rejected refresh no longer counts toward the IP ban: a client with an expired token was retrying into a self-renewing ban on its own IP. - 401s carry the RFC 9728 WWW-Authenticate discovery header.
This commit is contained in:
@@ -40,7 +40,12 @@ log = logging.getLogger("signal_bridge.oauth")
|
||||
# ════════════════════════════════════════════════════════════════════════
|
||||
|
||||
AUTH_CODE_EXPIRY_S = 300 # 5 minutes — per OAuth spec recommendation
|
||||
REFRESH_TOKEN_EXPIRY_S = 86400 * 30 # 30 days
|
||||
# Must comfortably outlive the access token (SB_TOKEN_EXPIRY_HOURS, often
|
||||
# 30 days): clients only refresh once the access token has expired, so a
|
||||
# refresh token with the same lifetime is already dead when it's needed.
|
||||
# Rotation issues a fresh one on every refresh, so active clients never
|
||||
# reach this limit.
|
||||
REFRESH_TOKEN_EXPIRY_S = 86400 * 90 # 90 days
|
||||
|
||||
|
||||
# ════════════════════════════════════════════════════════════════════════
|
||||
|
||||
Reference in New Issue
Block a user