lfs: transfer tokens outlive the revoked key #285

closed cmc opened this on 2026-09-28 05:23 UTC · keys security

Discussion

cmc 2026-09-28 05:23 UTC

An LFS transfer token outlives the key that obtained it.

lfs.Sign (internal/lfs/lfs.go:129) signs repo id, operation and expiry, with TokenTTL = time.Hour. The token names no user or key, and Verify checks only the HMAC and the expiry. After keys remove, repo deploy-key remove or account disable, a token already issued keeps working for downloads or uploads for up to an hour.

  • Include the key id (or user id) in the payload and check it still exists and is not disabled in Verify's caller, or shorten the TTL to what a transfer needs.
  • Relevant to #256, whose revocation is immediate for SSH and git transports.

referenced in commit fb6e9dcfa4 by cmc: plans: #287, #284, #298, #285, #297

2026-09-29 00:09 UTC

referenced in commit ceafd97e30 by cmc: lfs: refuse an upload token once its repository is archived

2026-09-29 02:17 UTC

closed by cmc in commit bd5cf5d7d1: lfs: e2e for a token outliving its key; document the binding

2026-09-29 02:17 UTC

referenced in commit b5cc83bf50 by cmc: lfs: test deploy key tokens

2026-09-29 02:17 UTC

referenced in commit 911c19309b by cmc: lfs: a token needs its key's current access to the repository

2026-09-29 02:17 UTC

referenced in commit 70d7e17c28 by cmc: lfs: refuse a token whose key was removed, expired or disabled

2026-09-29 02:17 UTC

referenced in commit 682aca3520 by cmc: lfs: a transfer token names the key that obtained it

2026-09-29 02:17 UTC