Skip to content

quest(auth): block the line on closing the session for a malformed AUTH_OK grant - #4380

Draft
kixelated wants to merge 2 commits into
quest/m1/auth/READMEfrom
audit/auth-blockers
Draft

kixelated wants to merge 2 commits into
quest/m1/auth/READMEfrom
audit/auth-blockers

Conversation

@kixelated

@kixelated kixelated commented Sep 28, 2026 •

Copy link
Copy Markdown
Collaborator

Problem

#4277 specified that a malformed or non-canonical grant pattern is a PROTOCOL_VIOLATION (drafts/draft-lcurley-moq-lite.md, Path Pattern), but Rust and JS only drop the token and keep the session up. Maintainer decisions from the 09-28 merged-PR audit: both implementations close the session with PROTOCOL_VIOLATION to match the draft (fail loud), with tests in both languages, before the line lands on main. The maintainer also decided that an out-of-range Expires in AUTH_OK closes the session the same way.

Approach

New child quest Malformed grant on the auth line (finding, decline). Verified still present on the line branch: Rust's PresentToken ends only the token on the decode error, and the JS #run loop in auth_session.ts catches it the same way.

The quest covers:

  • A malformed or non-canonical grant pattern closes the session with PROTOCOL_VIOLATION in Rust and JS.
  • An out-of-range Expires does the same (decided here). Rust already labels it a ProtocolViolation but only ends the token. The draft does not yet define "out of range", so the quest adds that definition to it.
  • Tests in both languages for all three cases (malformed pattern, non-canonical pattern, out-of-range Expires).

Impact

  • Quest files only. No API or wire change.

Alternatives

  • None considered.

Follow-ups

  • None beyond the new quest.

(Written by Opus 5.5)

🤖 Generated with Claude Code

kixelated and others added 2 commits September 28, 2026 10:42
…ant pattern

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@kixelated kixelated changed the title quest(auth): block the line on closing the session for a malformed grant pattern quest(auth): block the line on closing the session for a malformed AUTH_OK grant Sep 28, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant