Skip to content

feat(socrate): User.TokenVersion and User.Locked from the member look-up - #79

Merged
ovander merged 1 commit into
mainfrom
feat/socrate-user-token-version
Oct 3, 2026
Merged

ovander merged 1 commit into
mainfrom
feat/socrate-user-token-version

Conversation

@ovander

@ovander ovander commented Oct 3, 2026

Copy link
Copy Markdown
Owner

What and why

Socrate v1.8.0 (ovander/go-oauth2#299) returns token_version and locked on the single-member look-up. This PR exposes them as socrate.User.TokenVersion *int and socrate.User.Locked *bool.

A resource server can then call GetUserAsService with its cached service token to check whether a user token was revoked: the token was revoked if its token_version claim is lower than *TokenVersion. Revocations covered: sign-out, password change or reset, block, "revoke all tokens", and refresh-token reuse. This is cheaper than introspection, which runs a bcrypt client authentication on every call.

The fields stay nil when the user comes from a list or from an older Socrate. A single token revoked through /oauth/revoke does not change token_version; introspection is still the way to see that (stated in the doc comment). Lakebridge asked for this.

How it was tested

TestGetUserAsService_TokenVersionAndLocked covers both servers: from v1.8.0 the fields are filled; from an older Socrate they stay nil.

  • go mod tidy && git diff --exit-code go.sum leaves go.sum unchanged
  • go build ./... passes
  • go vet ./... passes
  • go test -race -count=1 -timeout=120s ./... passes
  • golangci-lint run ./... (v2.14.0) reports no issue
  • govulncheck ./... not run (the sandbox can't reach vuln.go.dev); CI runs it
  • A line is added under ## [Unreleased] in CHANGELOG.md

Compatibility

  • Exported-API change: yes. Two new optional fields on socrate.User: TokenVersion, Locked.
  • Behaviour change for existing callers: none (pointer fields, omitempty).
  • Breaking change: none.

🤖 Generated with Claude Code

https://claude.ai/code/session_01GKRxaeYxyDhmt42cehLsGA


Generated by Claude Code

Socrate v1.8.0 returns token_version and locked on the single-member
look-up (GET /api/apps/{id}/service/users/{user_id} and the user-token
route). Expose them as optional pointer fields so a resource server can
check user-token revocation with its cached service token. Nil from
lists and older servers; additive.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GKRxaeYxyDhmt42cehLsGA
@ovander
ovander merged commit 3220774 into main Oct 3, 2026
6 checks passed
@ovander ovander mentioned this pull request Oct 3, 2026
7 tasks done
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants