feat: configurable CLI token TTL (CLI_TOKEN_TTL_DAYS, default 90d) #4

Merged
jknapp merged 1 commits from feat/configurable-cli-token-ttl into main 2026-06-12 19:01:41 +00:00
2 changed files with 25 additions and 1 deletions
Showing only changes of commit 684ff03db2 - Show all commits
+5
View File
@@ -70,6 +70,11 @@ NEXTAUTH_SECRET=replace-me-with-32-bytes-of-random
# ----------------------------------------------------------------------------- # -----------------------------------------------------------------------------
CLI_TOKEN_SECRET=replace-me-with-32-bytes-of-random CLI_TOKEN_SECRET=replace-me-with-32-bytes-of-random
# Lifetime (in days) of newly minted CLI tokens. Positive integer; unset or
# invalid values fall back to 90. Only affects tokens minted after this is set —
# already-issued tokens keep their original expiry.
# CLI_TOKEN_TTL_DAYS=90
# ----------------------------------------------------------------------------- # -----------------------------------------------------------------------------
# App # App
# ----------------------------------------------------------------------------- # -----------------------------------------------------------------------------
+20 -1
View File
@@ -29,7 +29,26 @@ import { cliTokens } from "@/lib/db/schema";
export const CLI_TOKEN_KID = "cli-v1"; export const CLI_TOKEN_KID = "cli-v1";
export const CLI_TOKEN_ISSUER = "shared-memory:cli"; export const CLI_TOKEN_ISSUER = "shared-memory:cli";
export const CLI_TOKEN_TTL_SECONDS = 60 * 60 * 24 * 30; // 30 days
// Default lifetime for newly minted CLI tokens. Overridable via the
// CLI_TOKEN_TTL_DAYS env var (must be a positive integer number of days);
// anything unset/invalid falls back to this default. Only affects tokens
// minted from now on — already-issued tokens keep their original `exp`.
const DEFAULT_CLI_TOKEN_TTL_DAYS = 90;
function cliTokenTtlSeconds(): number {
const raw = process.env.CLI_TOKEN_TTL_DAYS;
let days = DEFAULT_CLI_TOKEN_TTL_DAYS;
if (raw !== undefined && raw.trim() !== "") {
const parsed = Number(raw);
if (Number.isInteger(parsed) && parsed > 0) {
days = parsed;
}
}
return days * 60 * 60 * 24;
}
export const CLI_TOKEN_TTL_SECONDS = cliTokenTtlSeconds();
function secret(): Uint8Array { function secret(): Uint8Array {
return new TextEncoder().encode(env().CLI_TOKEN_SECRET); return new TextEncoder().encode(env().CLI_TOKEN_SECRET);