internal/lfs binds a transfer token to ssh_keys.id and internal/httpd/lfs.go checks only that id. ssh_keys is INTEGER PRIMARY KEY without AUTOINCREMENT and keys are hard-deleted, so removing the newest key and adding another gives the new key the same id, and a stolen token works again for the rest of its hour (or carries another user's access if their key takes the id). Bind the token to the key's fingerprint as well and compare it on each request.
closed by cmc in commit fc755889ba: lfs: tokens carry the key's fingerprint pin beside its id
2026-09-29 02:39 UTC