fix(security): require auth on every MCP request; stop stale refreshes banning clients

- Remove the authless "sole connected phone" fallback and SB_REQUIRE_MCP_AUTH:
  an unauthenticated request no longer reaches whichever phone is online alone.
- Mcp-Session-Id is no longer a credential; the Bearer token is checked on
  every request (MCP auth spec).
- Refresh tokens live 90 days (was 30, equal to the access token, so they
  were always dead when first needed).
- A rejected refresh no longer counts toward the IP ban: a client with an
  expired token was retrying into a self-renewing ban on its own IP.
- 401s carry the RFC 9728 WWW-Authenticate discovery header.
This commit is contained in:
AletheiaVox
2026-09-27 12:55:16 +02:00
parent 605f71b742
commit 7bb9d8473b
9 changed files with 124 additions and 53 deletions

View File

@@ -154,14 +154,6 @@ class SessionRegistry:
async with self._lock:
return dict(self._sessions)
async def get_sole_user_id(self) -> Optional[str]:
"""If exactly one phone session is active, return its user_id.
Used for authless MCP access (e.g. claude.ai connector)."""
async with self._lock:
if len(self._sessions) == 1:
return next(iter(self._sessions))
return None
@property
def active_count(self) -> int:
return len(self._sessions)