Add inactivity-based session timeout (closes #66) (#105)
All checks were successful
check / check (push) Successful in 4s
All checks were successful
check / check (push) Successful in 4s
Sessions now carry a server-enforced idle deadline (SESSION_IDLE_TIMEOUT, default 24h) alongside the 7-day absolute cap, refreshed on authenticated activity. Activity never extends the absolute cap.
This commit was merged in pull request #105.
This commit is contained in:
@@ -10,6 +10,7 @@ import (
|
||||
"log/slog"
|
||||
"maps"
|
||||
"net/http"
|
||||
"time"
|
||||
|
||||
"github.com/gorilla/sessions"
|
||||
"go.uber.org/fx"
|
||||
@@ -32,6 +33,18 @@ const (
|
||||
// status.
|
||||
AuthenticatedKey = "authenticated"
|
||||
|
||||
// CreatedAtKey is the session key holding the Unix timestamp at
|
||||
// which the session was authenticated. It anchors the ABSOLUTE
|
||||
// expiry clock and is written exactly once, by SetUser. Nothing
|
||||
// refreshes it: an absolute deadline that moved with activity
|
||||
// would not be a cap at all.
|
||||
CreatedAtKey = "created_at"
|
||||
|
||||
// LastSeenKey is the session key holding the Unix timestamp of
|
||||
// the most recent authenticated request. It anchors the IDLE
|
||||
// expiry clock and is pushed forward by Touch.
|
||||
LastSeenKey = "last_seen"
|
||||
|
||||
// sessionKeyLength is the required length in bytes for the
|
||||
// session authentication key.
|
||||
sessionKeyLength = 32
|
||||
@@ -41,6 +54,19 @@ const (
|
||||
|
||||
// secondsPerDay is the number of seconds in a day.
|
||||
secondsPerDay = 86400
|
||||
|
||||
// sessionAbsoluteMaxAge is the hard upper bound on how long a
|
||||
// session may live, measured from CreatedAtKey. Activity never
|
||||
// extends it, so even a continuously used session ends here and
|
||||
// the user has to authenticate again.
|
||||
sessionAbsoluteMaxAge = sessionMaxAgeDays * secondsPerDay * time.Second
|
||||
|
||||
// idleRefreshDivisor rate-limits idle-deadline refreshes. Touch
|
||||
// only rewrites LastSeenKey once the stored value is older than
|
||||
// idleTimeout/idleRefreshDivisor, so an active session is
|
||||
// re-saved at most this many times per idle window instead of
|
||||
// once per request. See Touch for the tradeoff this buys.
|
||||
idleRefreshDivisor = 10
|
||||
)
|
||||
|
||||
// ErrSessionKeyLength is returned when the decoded session key
|
||||
@@ -62,6 +88,16 @@ type Session struct {
|
||||
key []byte // raw 32-byte auth key, also used for CSRF cookie signing
|
||||
log *slog.Logger
|
||||
config *config.Config
|
||||
|
||||
// idleTimeout is the sliding inactivity window. A session that
|
||||
// sees no authenticated request within this window expires,
|
||||
// independently of the absolute cap. Non-positive disables idle
|
||||
// expiry and leaves sessionAbsoluteMaxAge as the only bound.
|
||||
idleTimeout time.Duration
|
||||
|
||||
// now reads the current time. Injected so expiry can be tested
|
||||
// without sleeping.
|
||||
now func() time.Time
|
||||
}
|
||||
|
||||
// New creates a new session manager. The cookie store is
|
||||
@@ -73,8 +109,10 @@ func New(
|
||||
params Params,
|
||||
) (*Session, error) {
|
||||
s := &Session{
|
||||
log: params.Logger.Get(),
|
||||
config: params.Config,
|
||||
log: params.Logger.Get(),
|
||||
config: params.Config,
|
||||
idleTimeout: params.Config.SessionIdleTimeout,
|
||||
now: time.Now,
|
||||
}
|
||||
|
||||
lc.Append(fx.Hook{
|
||||
@@ -149,29 +187,98 @@ func (s *Session) Save(
|
||||
return sess.Save(r, w)
|
||||
}
|
||||
|
||||
// SetUser sets the user information in the session.
|
||||
// SetUser sets the user information in the session. It starts both
|
||||
// expiry clocks: CreatedAtKey (absolute, never refreshed again) and
|
||||
// LastSeenKey (idle, refreshed by Touch).
|
||||
func (s *Session) SetUser(
|
||||
sess *sessions.Session,
|
||||
userID, username string,
|
||||
) {
|
||||
now := s.now().Unix()
|
||||
|
||||
sess.Values[UserIDKey] = userID
|
||||
sess.Values[UsernameKey] = username
|
||||
sess.Values[AuthenticatedKey] = true
|
||||
sess.Values[CreatedAtKey] = now
|
||||
sess.Values[LastSeenKey] = now
|
||||
}
|
||||
|
||||
// ClearUser removes user information from the session.
|
||||
// ClearUser removes user information from the session, including
|
||||
// both expiry timestamps.
|
||||
func (s *Session) ClearUser(sess *sessions.Session) {
|
||||
delete(sess.Values, UserIDKey)
|
||||
delete(sess.Values, UsernameKey)
|
||||
delete(sess.Values, AuthenticatedKey)
|
||||
delete(sess.Values, CreatedAtKey)
|
||||
delete(sess.Values, LastSeenKey)
|
||||
}
|
||||
|
||||
// IsAuthenticated checks if the session has an authenticated
|
||||
// user.
|
||||
// sessionTime reads a Unix-second timestamp stored under key.
|
||||
func sessionTime(
|
||||
sess *sessions.Session,
|
||||
key string,
|
||||
) (time.Time, bool) {
|
||||
secs, ok := sess.Values[key].(int64)
|
||||
if !ok {
|
||||
return time.Time{}, false
|
||||
}
|
||||
|
||||
return time.Unix(secs, 0), true
|
||||
}
|
||||
|
||||
// IsAuthenticated checks if the session has an authenticated user
|
||||
// whose session has not passed either expiry deadline. Every
|
||||
// authentication decision goes through here, so neither clock can
|
||||
// be bypassed by a caller that forgets to check it.
|
||||
func (s *Session) IsAuthenticated(sess *sessions.Session) bool {
|
||||
auth, ok := sess.Values[AuthenticatedKey].(bool)
|
||||
if !ok || !auth {
|
||||
return false
|
||||
}
|
||||
|
||||
return ok && auth
|
||||
return !s.expired(sess)
|
||||
}
|
||||
|
||||
// Touch records authenticated activity by pushing the IDLE deadline
|
||||
// forward. It writes LastSeenKey only; CreatedAtKey is left alone so
|
||||
// the absolute cap keeps counting down even for a user who never
|
||||
// stops clicking.
|
||||
//
|
||||
// Callers must only invoke Touch for a request that authenticated
|
||||
// with this session. Refreshing on an unauthenticated request would
|
||||
// let anyone holding a stolen or abandoned cookie keep the session
|
||||
// alive by polling a public endpoint. Touch enforces that itself by
|
||||
// returning false for any session that is not currently
|
||||
// authenticated and unexpired.
|
||||
//
|
||||
// To avoid re-encrypting and re-emitting the session cookie on every
|
||||
// single request, the timestamp is advanced only once it is older
|
||||
// than idleTimeout/idleRefreshDivisor. The tradeoff is that
|
||||
// LastSeenKey lags real activity by up to that much, so a session
|
||||
// can expire slightly early relative to the user's true last
|
||||
// request -- never late.
|
||||
//
|
||||
// Touch reports whether it changed the session; only then does the
|
||||
// caller need to save it.
|
||||
func (s *Session) Touch(sess *sessions.Session) bool {
|
||||
if s.idleTimeout <= 0 {
|
||||
return false
|
||||
}
|
||||
|
||||
if !s.IsAuthenticated(sess) {
|
||||
return false
|
||||
}
|
||||
|
||||
now := s.now()
|
||||
|
||||
lastSeen, ok := sessionTime(sess, LastSeenKey)
|
||||
if ok && now.Sub(lastSeen) < s.idleTimeout/idleRefreshDivisor {
|
||||
return false
|
||||
}
|
||||
|
||||
sess.Values[LastSeenKey] = now.Unix()
|
||||
|
||||
return true
|
||||
}
|
||||
|
||||
// GetUserID retrieves the user ID from the session.
|
||||
@@ -253,3 +360,41 @@ func (s *Session) Regenerate(
|
||||
|
||||
return newSess, nil
|
||||
}
|
||||
|
||||
// expired reports whether the session has passed either of its two
|
||||
// independent deadlines. They are deliberately kept apart:
|
||||
//
|
||||
// - the ABSOLUTE deadline is CreatedAtKey + sessionAbsoluteMaxAge.
|
||||
// It is fixed at login and no amount of activity moves it.
|
||||
// - the IDLE deadline is LastSeenKey + idleTimeout. Activity moves
|
||||
// it forward via Touch.
|
||||
//
|
||||
// Whichever comes first ends the session.
|
||||
//
|
||||
// A session that claims to be authenticated but carries no
|
||||
// timestamps predates this check; it is treated as expired so the
|
||||
// user re-authenticates rather than being granted an unbounded
|
||||
// session.
|
||||
func (s *Session) expired(sess *sessions.Session) bool {
|
||||
now := s.now()
|
||||
|
||||
createdAt, ok := sessionTime(sess, CreatedAtKey)
|
||||
if !ok {
|
||||
return true
|
||||
}
|
||||
|
||||
if !now.Before(createdAt.Add(sessionAbsoluteMaxAge)) {
|
||||
return true
|
||||
}
|
||||
|
||||
if s.idleTimeout <= 0 {
|
||||
return false
|
||||
}
|
||||
|
||||
lastSeen, ok := sessionTime(sess, LastSeenKey)
|
||||
if !ok {
|
||||
return true
|
||||
}
|
||||
|
||||
return !now.Before(lastSeen.Add(s.idleTimeout))
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user