Skip to content

4.4 Add invitation expiration validation #334

@marwannettour

Description

@marwannettour

Parent epic: #310

Summary

Reject trusted-session invitations after expiration.

Requirements

  • Compare the current time with payload.ExpiresAt.
  • Return a clear user-facing expired result.
  • Send an Expired status back to the initiator where the relay flow supports it.
  • Apply any clock tolerance consistently if introduced.

Acceptance criteria

  • Expired invitations are refused.
  • Non-expired invitations continue through validation.
  • Expiration failures are test-covered.

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Type

    No fields configured for Task.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions