Skip to content

Commit fb0985e

Browse files
committed
Format changeset
1 parent 10fb6dd commit fb0985e

1 file changed

Lines changed: 1 addition & 1 deletion

File tree

‎.changeset/expired-authorization-session-sweep.md‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -4,6 +4,6 @@
44

55
**Abandoned authorization sessions no longer keep their PKCE verifier forever**
66

7-
An OAuth authorization session stores its PKCE verifier so the callback can redeem the code. `complete` discarded an expired session lazily, but an *abandoned* flow is never completed, so that check never ran for it and nothing else swept the table — the verifier sat there in plaintext indefinitely.
7+
An OAuth authorization session stores its PKCE verifier so the callback can redeem the code. `complete` discarded an expired session lazily, but an _abandoned_ flow is never completed, so that check never ran for it and nothing else swept the table — the verifier sat there in plaintext indefinitely.
88

99
Starting a new authorization now sweeps sessions that have already expired. Doing it on `start` bounds the table by how often authorization is begun rather than by how often it is abandoned, and needs no scheduler in any host. A session whose completion cannot be retried is dropped rather than left behind.

0 commit comments

Comments
 (0)