App Password cache: per-User revocation generation (one User's change must not make others re-verify or see 503) #587

Open
opened 2026-10-01 07:22:15 +00:00 by kayg · 0 comments
Owner

Follow-up from #512 round 2 (job/apw-cache-review e076d6112)

Revocation is fenced by one global generation counter. So any authority change (one User's demotion, disable or App Password scope change) invalidates every User's cached verifications, and "unrelated authority changes can briefly return retryable 503". On a multi-user server, one admin action makes everyone's CalDAV/WebDAV clients re-verify (expensive argon2 checks) and may see 503s.
Fix: per-User (and per-credential) generation counters. A change bumps only the affected User's generation; other Users keep their cache and never see a 503. Keep the existing proof tests (1,000 live revocations, 4,000 multi-worker transitions), and add one: User A's demotion causes zero cache misses and zero 503s for User B (50 clients).
Per-crate gates (calternal-auth, calternal-server). Non-blocking for the #512 merge; a fast follow-up.

## Follow-up from #512 round 2 (job/apw-cache-review e076d6112) Revocation is fenced by **one global generation counter**. So any authority change (one User's demotion, disable or App Password scope change) invalidates every User's cached verifications, and "unrelated authority changes can briefly return retryable 503". On a multi-user server, one admin action makes everyone's CalDAV/WebDAV clients re-verify (expensive argon2 checks) and may see 503s. **Fix:** per-User (and per-credential) generation counters. A change bumps only the affected User's generation; other Users keep their cache and never see a 503. Keep the existing proof tests (1,000 live revocations, 4,000 multi-worker transitions), and add one: User A's demotion causes **zero** cache misses and zero 503s for User B (50 clients). Per-crate gates (calternal-auth, calternal-server). Non-blocking for the #512 merge; a fast follow-up.
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
kayg/calternal#587
No description provided.