auth: add clock-skew leeway to JWT expiry validation #523

Open
opened 2026-08-04 11:35:25 +00:00 by the.auditor · 0 comments
Owner

internal/auth/auth.go uses jwt.WithLeeway(0). Valid Authentik tokens that expire within the leeway window of the daemon's clock are rejected under even small client/server clock skew.

Context: PR #521 (internal/auth/auth.go:88).

Suggested fix: use a small leeway (e.g. 30s–60s) via jwt.WithLeeway(time.Second * 30).

`internal/auth/auth.go` uses `jwt.WithLeeway(0)`. Valid Authentik tokens that expire within the leeway window of the daemon's clock are rejected under even small client/server clock skew. Context: PR #521 (`internal/auth/auth.go:88`). Suggested fix: use a small leeway (e.g. 30s–60s) via `jwt.WithLeeway(time.Second * 30)`.
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
thwap/thwap-pagesd#523
No description provided.