Skip to content

fix: preserve non-expiring access key authorizations - #862

Merged
gakonst merged 3 commits into
mainfrom
fix/non-expiring-access-keys
Oct 6, 2026
Merged

gakonst merged 3 commits into
mainfrom
fix/non-expiring-access-keys

Conversation

@gakonst

@gakonst gakonst commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

A device-code approval with expiry: 0 could return a valid non-expiring authorization but leave zero in local metadata, causing Accounts to discard it as expired. Normalize zero when preparing, importing, updating, and hydrating grants, and recognize legacy zero metadata during selection.

Omitted limits/scopes remain unrestricted; explicit empty lists remain restrictive. Finite expiries and on-chain missing/revoked-key checks retain their semantics. No new permissions or admin authority are introduced.

The base dependency tree subsequently failed the required audit with 11 active advisories. Update vulnerable transitive packages to published fixes, and replace the @istanbuljs/load-nyc-config YAML dependency with API-compatible js-yaml v4 to remove unpatched sprintf-js. Audit exclusions, trust policy, and CI gates are unchanged.

Validation:

  • Original implementation passed all 1,267 runtime tests across 49 files in CI, plus TypeScript and focused local tests.
  • The device-code fixture checks root signatures, canonical RPC expiry, reload/future selection, chain isolation, omitted/empty permissions, denial/timeout, and failed/successful revocation forwarding.
  • Updated dependency tree: frozen install succeeds and pnpm audit exits 0 with no active advisories (four previously ignored high findings remain).
  • Compatibility smoke checks pass for NYC YAML config loading with extends/arrays/scalars and KaTeX rendering with untrusted URL restrictions.
  • Updated-head pnpm -w check, pnpm -w build, and full pnpm check:types pass. Pure suite passes 641 tests in 40 files.
  • Full hosted runtime/localnet and required Checks must pass before merge.

The HTTP fixture uses a synthetic root and keystore. CI uses localnet; no real funds or user credentials are used by the tests.

@vercel

vercel Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
accounts-site Ready Ready Preview Oct 6, 2026 6:18am UTC

Request Review

@pkg-pr-new

pkg-pr-new Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

Open in StackBlitz

npm i https://pkg.pr.new/tempoxyz/accounts@862

commit: dcb2970

@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor
Worker Preview
Playground https://a30c1b8a-accounts-playground.porto.workers.dev

@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor
Worker Preview
Wagmi https://fb372761-accounts-wagmi.porto.workers.dev

@gakonst
gakonst marked this pull request as ready for review October 6, 2026 05:48
@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor
Worker Preview
Playground https://c4651916-accounts-playground.porto.workers.dev

@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor
Worker Preview
Wagmi https://8f62c9d9-accounts-wagmi.porto.workers.dev

@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor
Worker Preview
Wagmi https://422f3432-accounts-wagmi.porto.workers.dev

@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor
Worker Preview
Playground https://752613b6-accounts-playground.porto.workers.dev

@gakonst
gakonst merged commit 232cc59 into main Oct 6, 2026
14 checks passed
@gakonst
gakonst deleted the fix/non-expiring-access-keys branch October 6, 2026 06:21

This branch was successfully deployed

1 active deployment
Preview — dcb29702 Deployed Oct 6, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants