fix: add probabilistic cleanup to token blacklist

The blacklist table grew indefinitely since cleanup only ran on
password changes and user deletions. Now each blacklist_token()
call has a 2% chance of triggering blacklist_expired() to prune
expired entries. Redundant cleanup calls in update_password()
and delete_user() are removed.
This commit is contained in:
2026-07-29 03:41:15 +00:00
parent 48f8d0be18
commit 43b44ad340
2 changed files with 3 additions and 8 deletions
-8
View File
@@ -13,7 +13,6 @@ from typing import Any
from lib.auth import (
blacklist_active_refresh_token,
blacklist_expired,
rotate_user_secret,
)
from lib.db import (
@@ -205,7 +204,6 @@ def update_password(username: str, old_password: str, new_password: str) -> bool
rotate_user_secret(username)
db = get_db()
db.run(Q_UPDATE_PASSWORD, (new_hash, username))
_cleanup_blacklist()
return True
@@ -284,10 +282,4 @@ def delete_user(username: str) -> bool:
blacklist_active_refresh_token(username)
db = get_db()
db.run(Q_DELETE_USER, (username,))
_cleanup_blacklist()
return True
def _cleanup_blacklist() -> None:
"""Clean up expired blacklist entries."""
blacklist_expired()