Repository navigation
feat(socrate): User.TokenVersion and User.Locked from the member look-up - #79
Merged
Merged
Conversation
Socrate v1.8.0 returns token_version and locked on the single-member
look-up (GET /api/apps/{id}/service/users/{user_id} and the user-token
route). Expose them as optional pointer fields so a resource server can
check user-token revocation with its cached service token. Nil from
lists and older servers; additive.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GKRxaeYxyDhmt42cehLsGA
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What and why
Socrate v1.8.0 (ovander/go-oauth2#299) returns
token_versionandlockedon the single-member look-up. This PR exposes them assocrate.User.TokenVersion *intandsocrate.User.Locked *bool.A resource server can then call
GetUserAsServicewith its cached service token to check whether a user token was revoked: the token was revoked if itstoken_versionclaim is lower than*TokenVersion. Revocations covered: sign-out, password change or reset, block, "revoke all tokens", and refresh-token reuse. This is cheaper than introspection, which runs a bcrypt client authentication on every call.The fields stay nil when the user comes from a list or from an older Socrate. A single token revoked through
/oauth/revokedoes not changetoken_version; introspection is still the way to see that (stated in the doc comment). Lakebridge asked for this.How it was tested
TestGetUserAsService_TokenVersionAndLockedcovers both servers: from v1.8.0 the fields are filled; from an older Socrate they stay nil.go mod tidy && git diff --exit-code go.sumleavesgo.sumunchangedgo build ./...passesgo vet ./...passesgo test -race -count=1 -timeout=120s ./...passesgolangci-lint run ./...(v2.14.0) reports no issuegovulncheck ./...not run (the sandbox can't reach vuln.go.dev); CI runs it## [Unreleased]inCHANGELOG.mdCompatibility
socrate.User:TokenVersion,Locked.omitempty).🤖 Generated with Claude Code
https://claude.ai/code/session_01GKRxaeYxyDhmt42cehLsGA
Generated by Claude Code