An LFS transfer token outlives the key that obtained it.
lfs.Sign (internal/lfs/lfs.go:129) signs repo id, operation and expiry, with TokenTTL = time.Hour. The token names no user or key, and Verify checks only the HMAC and the expiry. After keys remove, repo deploy-key remove or account disable, a token already issued keeps working for downloads or uploads for up to an hour.
- Include the key id (or user id) in the payload and check it still exists and is not disabled in
Verify's caller, or shorten the TTL to what a transfer needs. - Relevant to #256, whose revocation is immediate for SSH and git transports.
referenced in commit fb6e9dcfa4 by cmc: plans: #287, #284, #298, #285, #297
2026-09-29 00:09 UTC