Repository navigation
Conversation
A radio node stayed authenticated after its linked user_sessions row was revoked (logout, revoke-all, admin action, expiry), so commands and bridge polls kept running and delivering private messages; pending chat notifications also survived authentication changes, and idle expiry was coupled to sender-row retention. Validate the linked session on every command and poll and reset the identity when it is gone; reset (not delete) on idle expiry with separate row retention; discard pending notifications across QUIT, LOGIN and expiry; bind legacy sessions to their bridge on first authorized access. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
TITLE: PacketBBS: fail closed when the linked web session is revoked; reset state across auth transitions
Problem
A PacketBBS identity lives in
packet_bbs_sessions.user_idand is linked to an online session throughbbs_session_id→user_sessions.handleCommand()trustsuser_idonce it is set. If the linkeduser_sessionsrow is revoked (logout, revoke-all, an administrator action, expiry, or account deactivation), the radio node stays authenticated, and the next netmail, chat or post command still executes. Bridge polling likewise keeps delivering queued private messages.Impact
Revoking a user's session does not stop that user's radio node. Private messages can reach a node after its user logged out or was revoked.
Repair
Auth::validateSession()still accepts. If it doesn't, the identity is reset as on idle expiry: identity, link, context, drafts and pending notifications are cleared. The command answersSession expired. LOGIN again.without executing, a poll delivers nothing, and no replacement online session is created.PACKETBBS_SESSION_RETENTION_SECONDS(default 86400; documented in.env.example).docs/PacketBBS.mddocuments the lifecycle.Proof
tests/Integration/PacketBbsSessionLifecycleTest.php(21 tests) runs against an isolated PostgreSQL database, using session-local temp tables only. It is opt-in throughPACKETBBS_TEST_DSNand skips otherwise. It covers:/SENDruns;The existing
PacketBbsTextRendererTestand the rest oftests/Unitare unchanged. (Proof against a real PostgreSQL instance is recorded separately.)