Skip to content

Hardening: device-code grants are never pruned after expiry #692

Description

@emooreatx

src/auth/device_grant.rs: POST /v1/auth/device/code (:293) inserts a grant into the pending map with an expires_at (:33-51), and expiry is only checked on lookup (410 expired_token, ~:774, :936). Nothing retains/prunes expired entries, so the map only grows over the node's uptime. Not an exploit on its own (no auth is expected on the code-request leg of a device flow), but a long-lived node accumulates every code ever requested.

Ask: prune expired grants (on insert, or a periodic sweep), and cap pending grants per client_id.

Found by CIRISClient's identity-group review (CSD-055).

🤖 Generated with Claude Code

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions