Skip to content

v0.2.0

Choose a tag to compare

@wushilin wushilin released this 05 Sep 06:30
· 4 commits to master since this release

Share links: expiry and revocation are enforced by the server, with no help from the viewer

Read-only share links were already force-closed by a timer at expiry, but the enforcement had gaps that let a viewer socket outlive its token:

  • the force-close deadline came from a second lookup after the lease check, so a clock tick between the two left the socket with no deadline at all
  • the streaming loop was unbiased, so a busy output stream could keep winning the race against a deadline that had already fired
  • the deadline ran on the monotonic clock while expiry is wall-clock time, so a clock step could stretch a link
  • the minute sweep only dropped map entries; live viewers on an expired grant were never told

What changed

The write half of every viewer socket now lives inside a lease guard that is the only way to emit a frame. Every send re-checks the lease — wall-clock expiry and revocation, one predicate — and refuses once it is invalid. The termination paths consume the guard by value, so streaming after that is a compile error, not a runtime check. Validity is one-way: a lease that has expired or been revoked can never become valid again, and every way of invalidating a link fails the viewer identically (Close frame, then reconnects refused at the upgrade).

Layered on top so that no single mechanism is load-bearing:

  • the lease carries its own expiry, and the deadline is derived from it with sub-second precision
  • the select loop is biased toward the expiry and revocation arms
  • every viewer socket audits its own lease on a fixed 15 s tick
  • the scheduled sweep (every minute) explicitly signals viewers of expired grants before pruning them
  • resolve / list / create prune through the same signalling path

Nothing here depends on the viewer page polling status or disconnecting on its own; a client that disables that polling is closed by the server all the same.

Tests

New integration tests cover a viewer that never polls status being closed by the server within the token's lifetime, and a viewer being disconnected the moment its link is revoked, with reconnects refused in both cases. Unit tests cover the one-way validity of a lease across expiry, revocation and sweep.

Compatibility

No configuration changes. Token format is unchanged; links minted by 0.1.x keep working until they expire. Because the enforcement moved into the server, this release is a drop-in upgrade for anyone relying on share-link expiry.

Assets

Fully static musl builds, no shared-library dependencies:

File Platform
webshell-0.2.0-linux-x86_64-musl Linux x86_64
webshell-0.2.0-linux-aarch64-musl Linux aarch64

SHA-256 checksums are in SHA256SUMS.

Full Changelog: v0.1.6...v0.2.0