Ports the upstream auth audit fixes onto the kept auth feature:
- revoke sessions server-side via an in-memory jti denylist (B5):
createSession embeds the session id as the JWT jti, invalidateSession
denylists it for the max token lifetime, validateSession rejects
denylisted and jti-less (fail-closed) tokens; constant-time signature
comparison (B4). Adds session-denylist.ts + test.
- cover signToken/verifyToken/validateSession crypto paths without a
running Payload by stubbing the payload module (B8).
- derive clientIp server-side from trusted proxy headers and drop it from
the public sign-in input schema; thread it as a server-only request
context argument so a client can no longer spoof its rate-limit bucket
(B2).
- declare the auth-injected email (and displayName) in the users
collection-level DSR pii map so Art. 15 export and Art. 17 soft delete
cover them (A5). Adapted to the clean-slate collection set.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016j8z4VHjedXDTjEDNg7qHK