cirisnode/config.py:19 defines ACCESS_TOKEN_EXPIRE_MINUTES: int = 30 and the deployment templates set it per node, but cirisnode/api/auth/routes.py:17 has its own module constant:
ACCESS_TOKEN_EXPIRE_MINUTES = 60
and login_for_access_token uses that (routes.py:93), not settings.ACCESS_TOKEN_EXPIRE_MINUTES. So the env var has no effect on the tokens /auth/token issues; every node issues 60-minute tokens regardless of configuration. Found while reconciling CIRISCore's templates against the live .env (the template default said 30, live said 60, and neither mattered).
Fix: delete the module constant and use settings.ACCESS_TOKEN_EXPIRE_MINUTES; pick one default (CLAUDE.md's "Dev Setup" implies 60 via jwt_expire_minutes). Check auth/refresh for the same pattern.
cirisnode/config.py:19definesACCESS_TOKEN_EXPIRE_MINUTES: int = 30and the deployment templates set it per node, butcirisnode/api/auth/routes.py:17has its own module constant:and
login_for_access_tokenuses that (routes.py:93), notsettings.ACCESS_TOKEN_EXPIRE_MINUTES. So the env var has no effect on the tokens/auth/tokenissues; every node issues 60-minute tokens regardless of configuration. Found while reconciling CIRISCore's templates against the live.env(the template default said 30, live said 60, and neither mattered).Fix: delete the module constant and use
settings.ACCESS_TOKEN_EXPIRE_MINUTES; pick one default (CLAUDE.md's "Dev Setup" implies 60 viajwt_expire_minutes). Checkauth/refreshfor the same pattern.