CodeForPhilly / CodeForPhilly/codeforphilly-ng
auth: 'Sign out all devices' — expose sign-out-everywhere sentinel
- 主要语言
- TypeScript
- 星标
- 1
- 派生
- 1
- 平均合并
- 5 天 3 小时
- 30 天内合并 PR
- 9
描述
## What's missing
\`specs/behaviors/authorization.md\` describes a \`jti = '*'\` sentinel in the revocations sheet that revokes every JWT for a personId whose \`iat\` precedes the sentinel's \`revokedAt\`. The verifier-side code at \`apps/api/src/auth/revocation.ts\` fully implements the sentinel.
**But there's no way for a user to trigger it.** No API endpoint exposes "sign out all devices," and the Account screen (\`specs/screens/account.md\`) only offers "Sign out of this session." A user whose phone is lost can revoke that one session but can't blast every JWT issued before now.
## Fix shape
1. Add \`POST /api/auth/logout-all\` (or \`POST /api/auth/sessions/revoke-all\`) — writes a sentinel \`Revocation\` with \`jti = '*'\`, \`personId = caller.id\`, \`revokedAt = now\`.
2. Add a "Sign out of all devices" button to the Account settings screen (\`apps/web/src/screens/Account.tsx\`).
3. Update \`specs/api/auth.md\` endpoints table + \`specs/screens/account.md\` Actions table.
## Why it's worth the work
Compromised-device recovery is a real account-security need. The hard part (the verifier-side sentinel) is already done; this is just plumbing.
Identified during the 2026-05-30 post-cutover-blog spec-drift audit.
贡献指南
这个仓库没有索引到贡献指南
评估
这个 Issue 还没有评估数据。