From 43b44ad340bb4230753f6b0b59b41ffa850b14b0 Mon Sep 17 00:00:00 2001 From: Mike Teehan Date: Wed, 29 Jul 2026 03:41:15 +0000 Subject: [PATCH] fix: add probabilistic cleanup to token blacklist The blacklist table grew indefinitely since cleanup only ran on password changes and user deletions. Now each blacklist_token() call has a 2% chance of triggering blacklist_expired() to prune expired entries. Redundant cleanup calls in update_password() and delete_user() are removed. --- lib/auth.py | 3 +++ lib/auth_users.py | 8 -------- 2 files changed, 3 insertions(+), 8 deletions(-) diff --git a/lib/auth.py b/lib/auth.py index 16999f5..b2ac916 100644 --- a/lib/auth.py +++ b/lib/auth.py @@ -10,6 +10,7 @@ from __future__ import annotations import base64 import json import logging +import random import secrets import time import uuid @@ -322,6 +323,8 @@ def blacklist_token(jti: str, token_type: str = "access") -> None: db = get_db() ttl = get_refresh_ttl() if token_type == "refresh" else get_access_ttl() db.run(Q_INSERT_BLACKLIST, (jti, token_type, int(time.time()) + ttl)) + if random.random() < 0.02: + blacklist_expired() def is_blacklisted(jti: str) -> bool: diff --git a/lib/auth_users.py b/lib/auth_users.py index d69e312..b6a3abe 100644 --- a/lib/auth_users.py +++ b/lib/auth_users.py @@ -13,7 +13,6 @@ from typing import Any from lib.auth import ( blacklist_active_refresh_token, - blacklist_expired, rotate_user_secret, ) from lib.db import ( @@ -205,7 +204,6 @@ def update_password(username: str, old_password: str, new_password: str) -> bool rotate_user_secret(username) db = get_db() db.run(Q_UPDATE_PASSWORD, (new_hash, username)) - _cleanup_blacklist() return True @@ -284,10 +282,4 @@ def delete_user(username: str) -> bool: blacklist_active_refresh_token(username) db = get_db() db.run(Q_DELETE_USER, (username,)) - _cleanup_blacklist() return True - - -def _cleanup_blacklist() -> None: - """Clean up expired blacklist entries.""" - blacklist_expired()