Skip to content
Open
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
@@ -0,0 +1,2 @@
-- sdp:migration-compat: breaking
UPDATE api_keys SET status = 'revoked', revoked_at = sdp_datetime_now() WHERE status = 'active';

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Production keys will be revoked

This update has no devnet-only condition. The migration runner applies it to every database receiving this release, including production. If production has active API keys, deploying this migration will revoke them and their clients will lose access, contrary to the stated devnet-only rollout.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 security Bulk revocation misses cached keys

If more than 10,000 keys are active when this runs, the update gives them the same revoked_at value. The cache reconciler selects only 10,000 matching rows per tick, with no cursor; repaired rows still match its query, so later ticks can select them again instead of reaching the remaining keys. A remaining key cached as active can keep authenticating until its one-hour cache TTL expires, rather than being evicted on the next tick.

How this was verified: Authentication accepts cached active keys, and cache repair does not remove their database rows from the reconciler’s limited query.

Knowledge Base Used: Platform API service

Loading