Part of #117.
With absolute_timeout set, a sliding renewal can push expires_at, and with it the JWT exp and the backend TTL, past created_at + absolute_timeout. The session is rejected at the cap on the next read. Until then, the token and the stored record claim a longer life than the configuration allows.
Proposal
Clamp the renewed expires_at, and the TTL derived from it, to created_at + absolute_timeout. Add a regression test.
Part of #117.
With
absolute_timeoutset, a sliding renewal can pushexpires_at, and with it the JWTexpand the backend TTL, pastcreated_at + absolute_timeout. The session is rejected at the cap on the next read. Until then, the token and the stored record claim a longer life than the configuration allows.Proposal
Clamp the renewed
expires_at, and the TTL derived from it, tocreated_at + absolute_timeout. Add a regression test.