From 066776ae4b395aea2bd7d9ab8138d0cc3fe6376c Mon Sep 17 00:00:00 2001 From: Luke Curley Date: Mon, 28 Sep 2026 10:42:23 -0700 Subject: [PATCH 1/2] quest(auth): block the line on closing the session for a malformed grant pattern Co-Authored-By: Claude Opus 5.5 --- quest/m1/auth/README.md | 3 +++ quest/m1/auth/malformed-grant.md | 40 ++++++++++++++++++++++++++++++++ 2 files changed, 43 insertions(+) create mode 100644 quest/m1/auth/malformed-grant.md diff --git a/quest/m1/auth/README.md b/quest/m1/auth/README.md index 242ca019e1..f00c9bc68b 100644 --- a/quest/m1/auth/README.md +++ b/quest/m1/auth/README.md @@ -89,6 +89,9 @@ existing lite-06 ALPN. ## Quests +- [Malformed grant](/quest/m1/auth/malformed-grant.md) - a malformed or + non-canonical grant pattern closes the session with PROTOCOL_VIOLATION in + Rust and JS, as the draft says - [Origin narrowing](/quest/m1/auth/narrowing.md) - a live grant narrows in place: subscriptions outside it reset, publishes outside it abort, and relay revalidation stops closing the session diff --git a/quest/m1/auth/malformed-grant.md b/quest/m1/auth/malformed-grant.md new file mode 100644 index 0000000000..fe8f19a002 --- /dev/null +++ b/quest/m1/auth/malformed-grant.md @@ -0,0 +1,40 @@ +# [S] Malformed grant closes the session + +## Goal + +A moq-lite AUTH_OK carrying a malformed or non-canonical grant pattern closes +the session with PROTOCOL_VIOLATION, in Rust and in JS, as +`drafts/draft-lcurley-moq-lite.md` already says under Path Pattern. Today +both only end the offending token and leave the session up. + +## Plan + +[#4277](https://github.com/moq-dev/moq/pull/4277) specified the rule, but +Rust's `PresentToken` (`rs/moq-net/src/lite/session.rs`) turns the decode +error into that token's end, and the JS auth loop (`#run` in +`js/net/src/auth_session.ts`) catches it the same way. Codex flagged the +mismatch +([r4113773014](https://github.com/moq-dev/moq/pull/4277#discussion_r4113773014)). +The agent declined because every malformed AUTH reply behaves this way, and +proposed deciding it separately +([r4114097664](https://github.com/moq-dev/moq/pull/4277#discussion_r4114097664)). +The maintainer decided in the 09-28 merged-PR audit: fail loud and match the +draft, with tests in both languages. + +- A pattern that fails to parse or is not canonical (`/room`, `*/**`, a 33rd + segment) closes the whole session with PROTOCOL_VIOLATION, not just the + token. +- A refusal (AUTH_ERROR) and a peer that predates AUTH keep their current + meaning: those end the token, not the session. +- The same path already labels an out-of-range `Expires` a + ProtocolViolation that only ends the token. Closing on that too is the + natural generalization; confirm with the maintainer before widening beyond + patterns. + +Tests in Rust and JS send a malformed and a non-canonical pattern and assert +the session closes with PROTOCOL_VIOLATION. Add them to the interop suite if +a shared vector is easy, since both sides must agree. + +## Related + +- [In-band auth](/quest/m1/auth/README.md) - the line this blocks From 781b213e49940efdad83f3676168e819e5055008 Mon Sep 17 00:00:00 2001 From: Luke Curley Date: Mon, 28 Sep 2026 11:08:37 -0700 Subject: [PATCH 2/2] quest(auth): an out-of-range Expires also closes the session Co-Authored-By: Claude Opus 5.5 --- quest/m1/auth/README.md | 4 ++-- quest/m1/auth/malformed-grant.md | 28 ++++++++++++++++------------ 2 files changed, 18 insertions(+), 14 deletions(-) diff --git a/quest/m1/auth/README.md b/quest/m1/auth/README.md index f00c9bc68b..514798b1f7 100644 --- a/quest/m1/auth/README.md +++ b/quest/m1/auth/README.md @@ -90,8 +90,8 @@ existing lite-06 ALPN. ## Quests - [Malformed grant](/quest/m1/auth/malformed-grant.md) - a malformed or - non-canonical grant pattern closes the session with PROTOCOL_VIOLATION in - Rust and JS, as the draft says + non-canonical grant pattern, or an out-of-range `Expires`, closes the + session with PROTOCOL_VIOLATION in Rust and JS - [Origin narrowing](/quest/m1/auth/narrowing.md) - a live grant narrows in place: subscriptions outside it reset, publishes outside it abort, and relay revalidation stops closing the session diff --git a/quest/m1/auth/malformed-grant.md b/quest/m1/auth/malformed-grant.md index fe8f19a002..d3dc765a1a 100644 --- a/quest/m1/auth/malformed-grant.md +++ b/quest/m1/auth/malformed-grant.md @@ -2,10 +2,11 @@ ## Goal -A moq-lite AUTH_OK carrying a malformed or non-canonical grant pattern closes -the session with PROTOCOL_VIOLATION, in Rust and in JS, as -`drafts/draft-lcurley-moq-lite.md` already says under Path Pattern. Today -both only end the offending token and leave the session up. +A moq-lite AUTH_OK carrying a malformed or non-canonical grant pattern, or an +out-of-range `Expires`, closes the session with PROTOCOL_VIOLATION, in Rust +and in JS. `drafts/draft-lcurley-moq-lite.md` already says so for patterns +under Path Pattern. Today both implementations only end the offending token +and leave the session up. ## Plan @@ -26,14 +27,17 @@ draft, with tests in both languages. token. - A refusal (AUTH_ERROR) and a peer that predates AUTH keep their current meaning: those end the token, not the session. -- The same path already labels an out-of-range `Expires` a - ProtocolViolation that only ends the token. Closing on that too is the - natural generalization; confirm with the maintainer before widening beyond - patterns. - -Tests in Rust and JS send a malformed and a non-canonical pattern and assert -the session closes with PROTOCOL_VIOLATION. Add them to the interop suite if -a shared vector is easy, since both sides must agree. +- An out-of-range `Expires` closes the session the same way. Rust already + labels it a ProtocolViolation in `PresentToken` but only ends the token. + The maintainer decided this in + [#4380](https://github.com/moq-dev/moq/pull/4380). The draft does not say + what out of range means yet, so define it there, next to the other AUTH_OK + fields. Rust and JS must then refuse the same values. + +Tests in Rust and JS send a malformed pattern, a non-canonical pattern, and an +out-of-range `Expires`, and assert that the session closes with +PROTOCOL_VIOLATION. If a shared vector is easy, add them to the interop suite +as well, since both sides must agree. ## Related