Auth: bind passkey login and assertion writes to the current credential #1043

Closed
opened 2026-10-04 08:11:34 +00:00 by kayg · 4 comments
Owner

Found during the #1041 review on dev 6074f71d1. This is a separate passkey commit-boundary concern, not the App Password cache-change race.

Code inspection: PasskeyService::finish_login loads the credential, checks the assertion, and then calls issue_session. That issuance checks User state but does not bind the insert to the continued presence of the credential. finish_assertion also marks a session fresh after a separate credential read. remove_passkey deletes the row in its own transaction. There is no final credential-presence condition shared with session issuance or fresh-assertion marking.

Please add a deterministic local regression for removal between verification and the authority write, and bind those writes to the still-present credential in the same transaction. A completed removal must reject a late login or assertion result. This is an inspection finding; the complete WebAuthn interleaving has not been reproduced in #1041.

Found during the #1041 review on dev 6074f71d1. This is a separate passkey commit-boundary concern, not the App Password cache-change race. Code inspection: `PasskeyService::finish_login` loads the credential, checks the assertion, and then calls `issue_session`. That issuance checks User state but does not bind the insert to the continued presence of the credential. `finish_assertion` also marks a session fresh after a separate credential read. `remove_passkey` deletes the row in its own transaction. There is no final credential-presence condition shared with session issuance or fresh-assertion marking. Please add a deterministic local regression for removal between verification and the authority write, and bind those writes to the still-present credential in the same transaction. A completed removal must reject a late login or assertion result. This is an inspection finding; the complete WebAuthn interleaving has not been reproduced in #1041.
Author
Owner

Started #1043 on branch job/passkeybind-1043 at base 6074f71d18.

I will bind passkey login session issuance and assertion freshness to the credential's continued presence in the write transaction. The deterministic regression will pause after WebAuthn verification, complete removal, then resume the write without sleeps. I will avoid the App Password flight region used by #1041.

Started #1043 on branch job/passkeybind-1043 at base 6074f71d18abe73b2b4255acb564f275a9acc851. I will bind passkey login session issuance and assertion freshness to the credential's continued presence in the write transaction. The deterministic regression will pause after WebAuthn verification, complete removal, then resume the write without sleeps. I will avoid the App Password flight region used by #1041.
Author
Owner

The two deterministic regressions passed: completed_removal_rejects_verified_login and completed_removal_rejects_verified_assertion. Each registers two real software-authenticator credentials, verifies a signed assertion, pauses at a test-only barrier, completes remove_passkey, then resumes. Login returns InvalidToken without inserting a session; assertion returns InvalidToken and leaves asserted_at NULL. The pause uses barriers, with no sleeps.

The implementation checks credential ID and User ID in the session INSERT or freshness UPDATE. Login inserts asserted_at with the session instead of marking it in a second write. The shared session issuance helper is reused; the #1041 App Password flight region is unchanged. No dependency or migration changes are needed.

The two deterministic regressions passed: `completed_removal_rejects_verified_login` and `completed_removal_rejects_verified_assertion`. Each registers two real software-authenticator credentials, verifies a signed assertion, pauses at a test-only barrier, completes `remove_passkey`, then resumes. Login returns InvalidToken without inserting a session; assertion returns InvalidToken and leaves asserted_at NULL. The pause uses barriers, with no sleeps. The implementation checks credential ID and User ID in the session INSERT or freshness UPDATE. Login inserts asserted_at with the session instead of marking it in a second write. The shared session issuance helper is reused; the #1041 App Password flight region is unchanged. No dependency or migration changes are needed.
Author
Owner

Built #1043: passkey login session issuance and assertion freshness now check the still-present credential and its User ID in the authority write. Login writes freshness in the session insert transaction. Assertion uses one conditional UPDATE, which shares SQLite write serialization with removal.

Files: crates/calternal-auth/src/store.rs; crates/calternal-auth/src/passkey.rs.
Head SHA: 7ebe1edfa4
Branch: job/passkeybind-1043
Base: 6074f71d18
Fetched origin and merged origin/dev once before final gates: Already up to date.

Regression evidence: completed_removal_rejects_verified_login and completed_removal_rejects_verified_assertion passed. Both use verified software-authenticator signatures and barriers to pause before the write, complete removal, and resume without sleeps. The late login adds no session. The late assertion leaves asserted_at NULL. A third test covers successful writes, wrong ownership, missing credentials, and revoked sessions. Existing test expectations are unchanged. The App Password flight region used by #1041 is unchanged.

Decisions:

  • Reuse the shared session issuance helper with an optional credential condition. Ordinary and agent issuance retain their current behavior.
  • Return the existing InvalidToken error when the bound authority write affects no row.
  • Use a test-only barrier after cryptographic verification. No runtime hook is added.
  • No dependency or migration changes. cargo search webauthn-rs reports 0.6.1-dev; the existing 0.5.5 dependency stays unchanged.

Known gaps: the existing software authenticator does not implement resident credential selection. The login regression supplies the allow list and User handle, as the existing login test does. One existing ignored test remains ignored. No UI changes; UX gaps closed/left: not applicable.

For the merge round: run tests/adversarial/run.sh on the combined branch to check real-server authentication, authorization and hostile-input handling. Full adversarial matrices, server builds, and Mac interop remain with the merge round under the verification policy. No performance measurements: this is not a performance issue.

Validation: bun install --frozen-lockfile and bun run --cwd apps/web build passed. Rust gates used CARGO_PROFILE_DEV_DEBUG=line-tables-only, CARGO_INCREMENTAL=0, CARGO_BUILD_JOBS=4, OPENSSL_NO_VENDOR=1 and worktree target/tmp for TMPDIR. calternal-server was not touched. Doc comments reviewed before this report. cargo clean completed and generated web output was deleted. The worktree is clean.

Gate output verbatim:

cargo fmt --check: exit 0, no output.

cargo clippy -p calternal-auth --all-targets -- -D warnings:

    Checking calternal-auth v0.1.0 (/home/kayg/Developer/calternal-wt/passkeybind-1043/crates/calternal-auth)
    Finished `dev` profile [unoptimized + debuginfo] target(s) in 9.43s

cargo test -p calternal-auth -- --test-threads=4:

   Compiling calternal-auth v0.1.0 (/home/kayg/Developer/calternal-wt/passkeybind-1043/crates/calternal-auth)
    Finished `test` profile [unoptimized + debuginfo] target(s) in 28.85s
     Running unittests src/lib.rs (/home/kayg/build/targets/passkeybind-1043/debug/deps/calternal_auth-e74e8c79db2302d8)

running 92 tests
test api::cli_login::tests::redirect_is_loopback_only ... ok
test api::cli_login::tests::approval_requires_a_browser_cookie_without_bearer_override ... ok
test api::cli_login::tests::signed_out_browser_gets_a_sign_in_page_not_a_json_error ... ok
test api::tests::apple_profile_is_a_valid_plist_with_the_cal_dav_payload ... ok
test api::cli_login::tests::device_code_is_one_time_and_bound_to_verifier_and_web_user ... ok
test api::tests::agent_token_cannot_extract_account_authority ... ok
test api::tests::admin_lists_need_admin_scope_and_revocation_needs_fresh_assertion ... ok
test api::tests::ask_agent_scope_allows_reads_and_denies_write_methods ... ok
test api::tests::authority_routes_require_recent_assertion_on_same_session ... ok
test api::tests::forwarded_chain_uses_first_untrusted_hop_from_right ... ok
test api::tests::notes_profile_uses_implicit_tls_and_one_immutable_user_identity ... ok
test api::tests::auth_options_report_setup_and_signup_without_a_session ... ok
test api::tests::profile_tokens_expire_and_are_consumed_once ... ok
test api::tests::extractor_keeps_cookie_and_bearer_session_kinds_separate ... ok
test api::tests::session_cookie_outlives_the_browser_session ... ok
test api::tests::rate_limit_isolated_by_peer_ip ... ok
test error::tests::bounded_admission_has_retry_after ... ok
test api::tests::passkey_rename_security_summary_and_current_session ... ok
test oidc::tests::groups_authoritative_defaults_to_true_in_provider_config ... ok
test api::tests::sign_out_revokes_only_the_calling_session_without_fresh_assertion ... ok
test oidc::tests::existing_identity_reconciles_groups_by_default ... ok
test api::tests::browser_callback_finishes_only_in_the_starting_browser ... ok
test oidc::tests::non_authoritative_groups_only_set_initial_role ... ok
test passkey::tests::completed_removal_rejects_verified_assertion ... ok
test passkey::tests::completed_removal_rejects_verified_login ... ok
test passkey::tests::existing_registration_fails_after_initiating_session_revoked ... ok
test oidc::tests::groups_claim_maps_admin_and_guest ... ok
test profile_signing::tests::cms_profile_is_attached_der_sha256_and_contains_the_chain ... ok
test profile_signing::tests::expired_signing_certificate_is_rejected ... ok
test profile_signing::tests::status_hides_the_certificate_team_id ... ok
test profile_signing::tests::status_warns_when_the_chain_expires_within_thirty_days ... ok
test profile_signing::tests::unsigned_fallback_preserves_the_profile_bytes ... ok
test recovery::tests::checksum_and_normalization ... ok
test passkey::tests::setup_registration_then_simulated_usernameless_login ... ok
test store::tests::admin_reenrol_link_is_single_use ... ok
test store::tests::agent_token_has_data_scope_and_home_shares_limit ... ok
test store::tests::all_auth_migrations_run_in_order_on_an_empty_database ... ok
test store::tests::app_password_cache_coalesces_concurrent_misses ... ok
test store::tests::app_password_cache_rejects_expired_completion_and_hit ... ok
test oidc::tests::oidc_reauth_marks_only_initiating_session ... ok
test store::tests::app_password_cache_rejects_late_verification_after_invalidation ... ok
test store::tests::app_password_cache_rejects_in_flight_authority ... ok
test store::tests::app_password_digest_maps_preserve_constant_time_equality ... ok
test store::tests::app_password_cancellation_keeps_blocking_work_bounded ... ok
test store::tests::app_password_options_validate_protocols_and_home_prefixes ... ok
test store::tests::app_password_revoke_rejects_queued_verification ... ok
test store::tests::app_password_scope_migration_preserves_existing_caldav_rights ... ok
test store::tests::account_security_counts_legacy_codes_and_lists_issuers ... ok
test store::tests::display_names_refuse_bidi_and_control_characters ... ok
test store::tests::human_session_scopes_follow_role ... ok
test store::tests::invites_list_without_tokens_and_revoke_only_unconsumed ... ok
test store::tests::app_password_is_one_time_secret_bound_to_user_and_revocable ... ok
test store::tests::migration_revokes_unclassified_pre_scope_sessions ... ok
test store::tests::disabling_user_invalidates_app_password_authority ... ok
test store::tests::oidc_cannot_claim_first_user_or_owner_role ... ok
test store::tests::oidc_reconcile_downgrades_and_preserves_owner ... ok
test store::tests::passkey_authority_writes_bind_both_owners_and_live_sessions ... ok
test store::tests::pool_acquisition_timeout_is_unavailable_not_internal ... ok
test store::tests::profile_role_and_disable_changes_take_effect ... ok
test store::tests::quota_overrides_follow_invites_and_require_an_admin ... ok
test store::tests::records_an_admin_action_in_security_events ... ok
test store::tests::notes_scope_is_separate_auditable_and_bound_to_one_user ... ok
test store::tests::key_rotation_revokes_sessions_and_rejects_competing_recovery ... ok
test store::tests::rename_passkey_is_owner_only_and_validates_the_label ... ok
test store::tests::recovery_code_is_one_time ... ok
test store::tests::recovery_proof_is_checked_before_challenge ... ok
test store::tests::review_change_window_rejects_positive_writes ... ok
test store::tests::review_demotion_revokes_app_password ... ok
test store::tests::review_identity_bound_cache_key ... ok
test store::tests::review_invalid_credential_timing_distributions ... ignored, timing diagnostic; run once with --ignored --nocapture
test store::tests::review_cache_bounds_ttl_and_keyed_digest ... ok
test store::tests::review_round_two_late_unrelated_change_is_retryable ... ok
test store::tests::review_round_two_suffixes_share_credential_admission ... ok
test store::tests::review_round_two_unrelated_change_is_retryable ... ok
test store::tests::review_failed_attempts_and_two_user_cache_matrix ... ok
test oidc::tests::validates_nonce_audience_expiry_and_refreshes_rotated_key ... ok
test store::tests::review_mutations_reject_queued_verification ... ok
test store::tests::review_waiter_admission_is_bounded ... ok
test store::tests::revoke_all_keeps_only_current_and_requires_fresh_for_changes ... ok
test store::tests::role_and_disable_revoke_sessions_and_event_failure_rolls_back ... ok
test store::tests::review_ten_thousand_credentials_and_thousand_waiters ... ok
test store::tests::session_authority_answers_while_the_writer_pool_is_busy ... ok
test store::tests::sessions_are_kind_bound_and_revocable ... ok
test store::tests::scope_change_uses_shared_app_password_cache_invalidation ... ok
test store::tests::setup_is_single_use_under_concurrency ... ok
test store::tests::transfer_target_cannot_be_deleted_until_pending_transfer_finishes ... ok
test store::tests::unlink_oidc_keeps_a_credential_and_rolls_back_on_audit_failure ... ok
test store::tests::user_deletion_revokes_sessions_and_resumes_with_the_original_expiry ... ok
test store::tests::username_is_case_insensitive_and_invite_single_use ... ok
test store::tests::sessions_expire_at_idle_and_absolute_deadlines ... ok
test store::tests::review_user_and_secret_mutation_matrix ... ok
test store::tests::review_thousand_authority_changes_per_kind ... ok

test result: ok. 91 passed; 0 failed; 1 ignored; 0 measured; 0 filtered out; finished in 117.19s

   Doc-tests calternal_auth

running 0 tests

test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s

READY FOR MERGE: yes.

Built #1043: passkey login session issuance and assertion freshness now check the still-present credential and its User ID in the authority write. Login writes freshness in the session insert transaction. Assertion uses one conditional UPDATE, which shares SQLite write serialization with removal. Files: crates/calternal-auth/src/store.rs; crates/calternal-auth/src/passkey.rs. Head SHA: 7ebe1edfa4e26fb2783ac9f9eec99a256dda22df Branch: job/passkeybind-1043 Base: 6074f71d18abe73b2b4255acb564f275a9acc851 Fetched origin and merged origin/dev once before final gates: Already up to date. Regression evidence: completed_removal_rejects_verified_login and completed_removal_rejects_verified_assertion passed. Both use verified software-authenticator signatures and barriers to pause before the write, complete removal, and resume without sleeps. The late login adds no session. The late assertion leaves asserted_at NULL. A third test covers successful writes, wrong ownership, missing credentials, and revoked sessions. Existing test expectations are unchanged. The App Password flight region used by #1041 is unchanged. Decisions: - Reuse the shared session issuance helper with an optional credential condition. Ordinary and agent issuance retain their current behavior. - Return the existing InvalidToken error when the bound authority write affects no row. - Use a test-only barrier after cryptographic verification. No runtime hook is added. - No dependency or migration changes. cargo search webauthn-rs reports 0.6.1-dev; the existing 0.5.5 dependency stays unchanged. Known gaps: the existing software authenticator does not implement resident credential selection. The login regression supplies the allow list and User handle, as the existing login test does. One existing ignored test remains ignored. No UI changes; UX gaps closed/left: not applicable. For the merge round: run `tests/adversarial/run.sh` on the combined branch to check real-server authentication, authorization and hostile-input handling. Full adversarial matrices, server builds, and Mac interop remain with the merge round under the verification policy. No performance measurements: this is not a performance issue. Validation: bun install --frozen-lockfile and bun run --cwd apps/web build passed. Rust gates used CARGO_PROFILE_DEV_DEBUG=line-tables-only, CARGO_INCREMENTAL=0, CARGO_BUILD_JOBS=4, OPENSSL_NO_VENDOR=1 and worktree target/tmp for TMPDIR. calternal-server was not touched. Doc comments reviewed before this report. cargo clean completed and generated web output was deleted. The worktree is clean. Gate output verbatim: `cargo fmt --check`: exit 0, no output. `cargo clippy -p calternal-auth --all-targets -- -D warnings`: ``` Checking calternal-auth v0.1.0 (/home/kayg/Developer/calternal-wt/passkeybind-1043/crates/calternal-auth) Finished `dev` profile [unoptimized + debuginfo] target(s) in 9.43s ``` `cargo test -p calternal-auth -- --test-threads=4`: ``` Compiling calternal-auth v0.1.0 (/home/kayg/Developer/calternal-wt/passkeybind-1043/crates/calternal-auth) Finished `test` profile [unoptimized + debuginfo] target(s) in 28.85s Running unittests src/lib.rs (/home/kayg/build/targets/passkeybind-1043/debug/deps/calternal_auth-e74e8c79db2302d8) running 92 tests test api::cli_login::tests::redirect_is_loopback_only ... ok test api::cli_login::tests::approval_requires_a_browser_cookie_without_bearer_override ... ok test api::cli_login::tests::signed_out_browser_gets_a_sign_in_page_not_a_json_error ... ok test api::tests::apple_profile_is_a_valid_plist_with_the_cal_dav_payload ... ok test api::cli_login::tests::device_code_is_one_time_and_bound_to_verifier_and_web_user ... ok test api::tests::agent_token_cannot_extract_account_authority ... ok test api::tests::admin_lists_need_admin_scope_and_revocation_needs_fresh_assertion ... ok test api::tests::ask_agent_scope_allows_reads_and_denies_write_methods ... ok test api::tests::authority_routes_require_recent_assertion_on_same_session ... ok test api::tests::forwarded_chain_uses_first_untrusted_hop_from_right ... ok test api::tests::notes_profile_uses_implicit_tls_and_one_immutable_user_identity ... ok test api::tests::auth_options_report_setup_and_signup_without_a_session ... ok test api::tests::profile_tokens_expire_and_are_consumed_once ... ok test api::tests::extractor_keeps_cookie_and_bearer_session_kinds_separate ... ok test api::tests::session_cookie_outlives_the_browser_session ... ok test api::tests::rate_limit_isolated_by_peer_ip ... ok test error::tests::bounded_admission_has_retry_after ... ok test api::tests::passkey_rename_security_summary_and_current_session ... ok test oidc::tests::groups_authoritative_defaults_to_true_in_provider_config ... ok test api::tests::sign_out_revokes_only_the_calling_session_without_fresh_assertion ... ok test oidc::tests::existing_identity_reconciles_groups_by_default ... ok test api::tests::browser_callback_finishes_only_in_the_starting_browser ... ok test oidc::tests::non_authoritative_groups_only_set_initial_role ... ok test passkey::tests::completed_removal_rejects_verified_assertion ... ok test passkey::tests::completed_removal_rejects_verified_login ... ok test passkey::tests::existing_registration_fails_after_initiating_session_revoked ... ok test oidc::tests::groups_claim_maps_admin_and_guest ... ok test profile_signing::tests::cms_profile_is_attached_der_sha256_and_contains_the_chain ... ok test profile_signing::tests::expired_signing_certificate_is_rejected ... ok test profile_signing::tests::status_hides_the_certificate_team_id ... ok test profile_signing::tests::status_warns_when_the_chain_expires_within_thirty_days ... ok test profile_signing::tests::unsigned_fallback_preserves_the_profile_bytes ... ok test recovery::tests::checksum_and_normalization ... ok test passkey::tests::setup_registration_then_simulated_usernameless_login ... ok test store::tests::admin_reenrol_link_is_single_use ... ok test store::tests::agent_token_has_data_scope_and_home_shares_limit ... ok test store::tests::all_auth_migrations_run_in_order_on_an_empty_database ... ok test store::tests::app_password_cache_coalesces_concurrent_misses ... ok test store::tests::app_password_cache_rejects_expired_completion_and_hit ... ok test oidc::tests::oidc_reauth_marks_only_initiating_session ... ok test store::tests::app_password_cache_rejects_late_verification_after_invalidation ... ok test store::tests::app_password_cache_rejects_in_flight_authority ... ok test store::tests::app_password_digest_maps_preserve_constant_time_equality ... ok test store::tests::app_password_cancellation_keeps_blocking_work_bounded ... ok test store::tests::app_password_options_validate_protocols_and_home_prefixes ... ok test store::tests::app_password_revoke_rejects_queued_verification ... ok test store::tests::app_password_scope_migration_preserves_existing_caldav_rights ... ok test store::tests::account_security_counts_legacy_codes_and_lists_issuers ... ok test store::tests::display_names_refuse_bidi_and_control_characters ... ok test store::tests::human_session_scopes_follow_role ... ok test store::tests::invites_list_without_tokens_and_revoke_only_unconsumed ... ok test store::tests::app_password_is_one_time_secret_bound_to_user_and_revocable ... ok test store::tests::migration_revokes_unclassified_pre_scope_sessions ... ok test store::tests::disabling_user_invalidates_app_password_authority ... ok test store::tests::oidc_cannot_claim_first_user_or_owner_role ... ok test store::tests::oidc_reconcile_downgrades_and_preserves_owner ... ok test store::tests::passkey_authority_writes_bind_both_owners_and_live_sessions ... ok test store::tests::pool_acquisition_timeout_is_unavailable_not_internal ... ok test store::tests::profile_role_and_disable_changes_take_effect ... ok test store::tests::quota_overrides_follow_invites_and_require_an_admin ... ok test store::tests::records_an_admin_action_in_security_events ... ok test store::tests::notes_scope_is_separate_auditable_and_bound_to_one_user ... ok test store::tests::key_rotation_revokes_sessions_and_rejects_competing_recovery ... ok test store::tests::rename_passkey_is_owner_only_and_validates_the_label ... ok test store::tests::recovery_code_is_one_time ... ok test store::tests::recovery_proof_is_checked_before_challenge ... ok test store::tests::review_change_window_rejects_positive_writes ... ok test store::tests::review_demotion_revokes_app_password ... ok test store::tests::review_identity_bound_cache_key ... ok test store::tests::review_invalid_credential_timing_distributions ... ignored, timing diagnostic; run once with --ignored --nocapture test store::tests::review_cache_bounds_ttl_and_keyed_digest ... ok test store::tests::review_round_two_late_unrelated_change_is_retryable ... ok test store::tests::review_round_two_suffixes_share_credential_admission ... ok test store::tests::review_round_two_unrelated_change_is_retryable ... ok test store::tests::review_failed_attempts_and_two_user_cache_matrix ... ok test oidc::tests::validates_nonce_audience_expiry_and_refreshes_rotated_key ... ok test store::tests::review_mutations_reject_queued_verification ... ok test store::tests::review_waiter_admission_is_bounded ... ok test store::tests::revoke_all_keeps_only_current_and_requires_fresh_for_changes ... ok test store::tests::role_and_disable_revoke_sessions_and_event_failure_rolls_back ... ok test store::tests::review_ten_thousand_credentials_and_thousand_waiters ... ok test store::tests::session_authority_answers_while_the_writer_pool_is_busy ... ok test store::tests::sessions_are_kind_bound_and_revocable ... ok test store::tests::scope_change_uses_shared_app_password_cache_invalidation ... ok test store::tests::setup_is_single_use_under_concurrency ... ok test store::tests::transfer_target_cannot_be_deleted_until_pending_transfer_finishes ... ok test store::tests::unlink_oidc_keeps_a_credential_and_rolls_back_on_audit_failure ... ok test store::tests::user_deletion_revokes_sessions_and_resumes_with_the_original_expiry ... ok test store::tests::username_is_case_insensitive_and_invite_single_use ... ok test store::tests::sessions_expire_at_idle_and_absolute_deadlines ... ok test store::tests::review_user_and_secret_mutation_matrix ... ok test store::tests::review_thousand_authority_changes_per_kind ... ok test result: ok. 91 passed; 0 failed; 1 ignored; 0 measured; 0 filtered out; finished in 117.19s Doc-tests calternal_auth running 0 tests test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s ``` READY FOR MERGE: yes.
Author
Owner

Deployed to production (2026-10-04 ~11:33 IST, small round 5 = d0fc1f463)

Round: dev 6074f71d1 + job/apprevoke-1041 + job/passkeybind-1043 + job/lease-1042. Gates on the round: cargo fmt --check clean; clippy clean and tests green for calternal-auth (92 passed), calternal-db (45), calternal-plugin-notes (193), calternal-plugin-mail (46), calternal-server (163), 0 failed. Staging healthy first; production healthy in 9 s, no panics or errors.

## Deployed to production (2026-10-04 ~11:33 IST, small round 5 = d0fc1f463) Round: dev 6074f71d1 + job/apprevoke-1041 + job/passkeybind-1043 + job/lease-1042. Gates on the round: `cargo fmt --check` clean; clippy clean and tests green for calternal-auth (92 passed), calternal-db (45), calternal-plugin-notes (193), calternal-plugin-mail (46), calternal-server (163), 0 failed. Staging healthy first; production healthy in 9 s, no panics or errors.
kayg closed this issue 2026-10-04 09:33:25 +00:00
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
kayg/calternal#1043
No description provided.