fix(api): revoke every existing API key - #2198
multipletwigs wants to merge 1 commit into
Conversation
|
| @@ -0,0 +1,2 @@ | |||
| -- sdp:migration-compat: breaking | |||
| UPDATE api_keys SET status = 'revoked', revoked_at = sdp_datetime_now() WHERE status = 'active'; | |||
There was a problem hiding this comment.
Production keys will be revoked
This update has no devnet-only condition. The migration runner applies it to every database receiving this release, including production. If production has active API keys, deploying this migration will revoke them and their clients will lose access, contrary to the stated devnet-only rollout.
| @@ -0,0 +1,2 @@ | |||
| -- sdp:migration-compat: breaking | |||
| UPDATE api_keys SET status = 'revoked', revoked_at = sdp_datetime_now() WHERE status = 'active'; | |||
There was a problem hiding this comment.
Bulk revocation misses cached keys
If more than 10,000 keys are active when this runs, the update gives them the same revoked_at value. The cache reconciler selects only 10,000 matching rows per tick, with no cursor; repaired rows still match its query, so later ticks can select them again instead of reaching the remaining keys. A remaining key cached as active can keep authenticating until its one-hour cache TTL expires, rather than being evicted on the next tick.
How this was verified: Authentication accepts cached active keys, and cache repair does not remove their database rows from the reconciler’s limited query.
Knowledge Base Used: Platform API service
6ec6ccb to
cd57e57
Compare
Keys created before explicit roles can hold permissions beyond their role preset, and no update or rotate path corrects them. Devnet only, so revoke them all; integrators mint fresh keys from the dashboard.
cd57e57 to
3fd3722
Compare
Top of the stack, on #2182 (and #2197). Revokes every active API key so no key created before explicit roles can carry permissions beyond its role preset.
permissionscould keep them through a PATCH that omitspermissions, and could no longer rotate once refactor(api-keys): single dashboard-only create path with explicit roles #2182's preset check lands.status = 'revoked',revoked_atset), nothing is deleted.reconcile-revoked-api-key-cache.tsevicts non-active keys by recentrevoked_at, so the 1h cache TTL doesn't apply.-- sdp:migration-compat: breaking; the check rejects row rewrites without it.Verification:
check:migration-compatpasses against #2197's branch; no service in this repo orsdp-infraauthenticates with a stored SDP API key. Migration not applied to a live DB; no migration test.