Skip to content

fix(auth): extend default JWT access TTL to 30 days and make it configurable - #376

Merged
LUPENGHAN merged 2 commits into
1024XEngineer:mainfrom
yyy-router:fix/jwt-access-ttl
Aug 25, 2026
Merged

LUPENGHAN merged 2 commits into
1024XEngineer:mainfrom
yyy-router:fix/jwt-access-ttl

Conversation

@yyy-router

Copy link
Copy Markdown
Contributor

关联 issue:#375

概述

访问令牌默认有效期从 1 小时改为 30 天,并让 TIMEFLOW_JWT_ACCESS_TTL_SECONDS 环境变量真正生效。

改动

  • JWT_ACCESS_TTL_SECONDS:3600 → 30 * 24 * 60 * 60(30 天)。
  • _validate_configuration:从「必须等于常量」放宽为「必须 > 0」,env 变量可配置。
  • .env.example:TTL 值与注释更新。
  • 测试:校验用例更新 + 新增「自定义 TTL 可被接受」用例。

验证

  • 全量 pytest 97.32% 覆盖(≥95%);ruff check / ruff format / mypy 全绿。

注意

改 TTL 会让已签发的旧令牌因 exp - iat 不匹配而失效,上线后需全员重新登录一次。

@codecov

codecov Bot commented Aug 25, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

@fennoai fennoai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

JWT 服务对正数自定义 TTL 的解析、签发和校验逻辑保持一致,30 天默认值也已覆盖;但仓库推荐的 Docker Compose 启动路径没有把该变量注入 API 容器,因此配置能力尚未贯通主要部署入口。

本地已执行 git diff --check;当前 runner 未安装 uv,无法复跑 pytest。

View job run

Comment thread backend/.env.example

@LUPENGHAN LUPENGHAN left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

ok

@LUPENGHAN
LUPENGHAN merged commit c2793df into 1024XEngineer:main Aug 25, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants