fix(auth): port server-side session revocation and sign-in hardening

Ports the upstream auth audit fixes onto the kept auth feature:

- revoke sessions server-side via an in-memory jti denylist (B5):
  createSession embeds the session id as the JWT jti, invalidateSession
  denylists it for the max token lifetime, validateSession rejects
  denylisted and jti-less (fail-closed) tokens; constant-time signature
  comparison (B4). Adds session-denylist.ts + test.
- cover signToken/verifyToken/validateSession crypto paths without a
  running Payload by stubbing the payload module (B8).
- derive clientIp server-side from trusted proxy headers and drop it from
  the public sign-in input schema; thread it as a server-only request
  context argument so a client can no longer spoof its rate-limit bucket
  (B2).
- declare the auth-injected email (and displayName) in the users
  collection-level DSR pii map so Art. 15 export and Art. 17 soft delete
  cover them (A5). Adapted to our collection set (no username field).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016j8z4VHjedXDTjEDNg7qHK
This commit is contained in:
2026-07-12 23:53:43 +02:00
parent 8b114351a8
commit ac0bf80eca
10 changed files with 437 additions and 32 deletions

View File

@@ -0,0 +1,46 @@
/**
* In-memory JWT `jti` denylist backing server-side session revocation
* (audit finding B5).
*
* `AuthenticationService.createSession` mints a session id and embeds it in
* the JWT as `jti`; `invalidateSession(jti)` records it here and
* `validateSession` rejects any token whose `jti` is denylisted. Entries
* expire with the token they revoke (max session lifetime), so the map is
* self-pruning and cannot grow past the number of sign-outs per lifetime
* window.
*
* SINGLE-PROCESS LIMITATION: this denylist lives in process memory. It is
* correct for a single server process (the template's deployment shape) but
* revocations are NOT shared across processes/instances and do not survive
* restarts — a restarted process accepts a signed, unexpired token again.
* Multi-instance deployments must swap this for a shared store (Redis, DB)
* behind the same two methods.
*/
export class InMemorySessionDenylist {
/** jti -> epoch-ms after which the entry may be pruned. */
private readonly revoked = new Map<string, number>();
constructor(private readonly clock: () => number = () => Date.now()) {}
/**
* Record a revoked `jti`. `ttlSeconds` should be the maximum remaining
* token lifetime — after that, the token's own `exp` rejects it anyway.
*/
revoke(jti: string, ttlSeconds: number): void {
this.prune();
this.revoked.set(jti, this.clock() + ttlSeconds * 1000);
}
isRevoked(jti: string): boolean {
this.prune();
return this.revoked.has(jti);
}
/** Expiry-based pruning — runs on every access; the map stays small. */
private prune(): void {
const now = this.clock();
for (const [jti, expiresAt] of this.revoked) {
if (expiresAt <= now) this.revoked.delete(jti);
}
}
}