Repository navigation
feat: revoke tokens server-side on auth logout (best-effort RFC 7009) - #17
Merged
Merged
Conversation
campus auth logout previously only deleted local credentials, leaving the refresh token valid server-side until natural expiry. Logout now attempts RFC 7009 revocation of the refresh and access tokens before clearing local state. Revocation is best-effort by design: logout still succeeds when the auth server is unreachable or deployed without /oauth/revoke (currently the case on dev — tracked in nyjc-computing/campus#677), with a dim note that only local credentials were cleared. The logged-out no-op path makes no network calls. Also refreshed docs: PRD logout/authentication-flow sections, corrected the stale 'CAMPUS_ENV' login docstring (actual variable is CAMPUS_AUTH_URL) and the stale 'Configurable API endpoint' PRD line (flag removed in PR #11). Discovered en route and filed upstream: refresh_token grant unimplemented on the deployed dev server (nyjc-computing/campus#678), which breaks CLI auto-refresh live.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
campus auth logoutnow attempts server-side token revocation (RFC 7009) before clearing local credentials. Previously it only deleted the local keyring/file entries, leaving the refresh token valid on the auth server until natural expiry — a copied or stolen token survived logout entirely.Found during the 2026-10-01 auth posture review of campus-cli.
Design decisions
token_type_hinton each), both bound toclient_id=guest(public client — no secret).Server-side prerequisite
The auth server has no revocation endpoint today —
POST /auth/v1/oauth/revokereturns 404 on dev (probed 2026-10-01). Until it ships, every logout shows the dim note and clears locally; once it lands, revocation activates with no CLI change. Tracked as nyjc-computing/campus#677 (implementation notes for the server side are in that issue).Related upstream issues filed from this review:
campus auth refreshfail live today; tokens are effectively single-use until re-login. No CLI change needed; the CLI honors rotation already.Doc refresh (included)
docs/PRD.md: logout line and a new Logout section (best-effort RFC 7009 semantics); corrected the stale "Configurable API endpoint" line (flag removed in PR chore: CLI polish — surface device-code error detail, remove unwired --api-endpoint flag #11) to describe the actualCAMPUS_AUTH_URL/config/default resolution.campus_cli/auth/login.py: corrected the staleCAMPUS_ENVdocstring onauth login(the actual variable isCAMPUS_AUTH_URL).Test plan
revoke_token: RFC 7009 payload + 200→True, non-200→False, network error→False (84 total, all passing).ruff checkclean; pre-commit smoke and pre-push lint hooks pass.Verification note
Not exercised against the live dev server (a real
logoutwould revoke the developer's stored token); behavior is pinned by the mocked tests above, and the live 404/no-endpoint path is exactly what the degradation tests simulate.