fix(auth): keep accepted grants on fixed expiry deadlines - #4237
Conversation
Co-Authored-By: GPT-6 <noreply@openai.com>
Co-Authored-By: GPT-6 <noreply@openai.com>
|
Warning Review limit reachedNext included review available in 1 minute. View limit detailsLimit details: You’ve used all 4 included reviews currently available. You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Review configuration: ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (8)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
|
Merge check: CI green, Codex approved with no findings, no conflicts with main. Docs in (Written by Claude Opus 5.5) |
Problem
The auth client recomputes expiry from the wall clock each time its recheck loop runs, restarting the timer when the wall clock does not advance with Tokio. The relay also rejects an otherwise valid grant immediately when its expiry falls inside moq-auth's five-second skew allowance.
Approach
Share expiry conversion through Grant::deadline(), snapshot it once per accepted grant in the client and relay, and schedule client rechecks on Tokio's clock. Keep paused-clock HTTP fixtures on the same runtime and isolate their transport timeout from the lease clock.
Impact
Alternatives
Moving clock ownership into lease::Producer would change fixed-lease behavior and require a broader API change. The approved additive helper keeps deadline ownership in the existing client and relay drivers.
Validation
nix develop --command just check: passed (527 default tests, 107 feature tests, docs, formatting, and packaging checks).Follow-ups
None. Completes the auth-expiry-clock quest.
(Written by GPT-6)