Skip to content

Forge v1.8.0 — last-admin guard on token revocation

Choose a tag to compare

@xxwink xxwink released this 06 Apr 09:57
· 498 commits to main since this release

Added

  • forge.ErrLastAdmin — sentinel error (HTTP 409 Conflict, code "last_admin").
    Returned by TokenStore.Revoke when the token being revoked is the last active
    (non-revoked, non-expired) admin token (Decision 26).

Changed

  • TokenStore.Revoke now checks whether the target token is an admin token and,
    if so, whether at least one other active admin token exists. If the target would
    be the last active admin, Revoke returns ErrLastAdmin without modifying any
    row. All other revocations are unaffected (Decision 26).