Harden auth with revocable sessions, cookies, and single-login default.

Issue short-lived access JWTs backed by AuthSession rows, HttpOnly cookies with refresh rotation, idle timeout, session management UI, WebCRT ownership caps, and optional Redis login rate limits; new logins revoke other sessions by default.

Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
oliver 2026-08-06 14:13:37 +08:00
parent ba33ab5c4f
commit 20c2fcd496
34 changed files with 1462 additions and 149 deletions

View file

@ -61,6 +61,7 @@ const en = {
logs: "Audit logs",
users: "User admin",
apiKeys: "API keys",
sessions: "Sessions",
},
announce: {
a1: "Dark workbench shell is live — other modules follow the same palette.",
@ -97,6 +98,8 @@ const en = {
auditDesc: "Live task overview and operation logs",
apiKeys: "API Keys",
apiKeysDesc: "Issue MCP/script tokens per user with expiry",
sessions: "Login sessions",
sessionsDesc: "Review and revoke logins on other devices",
},
},
network: {
@ -519,6 +522,7 @@ const en = {
titleUsers: "Users",
titleAudit: "Audit",
titleApiKeys: "API Keys",
titleSessions: "Login sessions",
navUme: "UME",
netxApi: "netx api",
oclawBridge: "oclaw WSS",
@ -538,6 +542,18 @@ const en = {
loggingIn: "Signing in…",
loginFailed: "Login failed",
logout: "Sign out",
sessionsTitle: "Login sessions",
sessionsHint: "Manage browser/device logins for this account. Revoked sessions must sign in again.",
sessionsEmpty: "No active sessions.",
revokeOtherSessions: "Revoke other sessions",
revokeSession: "Revoke",
sessionCurrent: "Current",
sessionRevoked: "Session revoked",
sessionsRevokedOthers: "Revoked {{count}} other session(s)",
revokeCurrentConfirm: "This is your current session; revoking it requires signing in again. Continue?",
colSession: "Session",
colLastSeen: "Last seen",
colCreated: "Created",
usersTitle: "User management",
usersHint: "Only admins can create and manage local accounts.",
addUser: "Add user",
@ -614,7 +630,7 @@ const en = {
confirmPassword: "Confirm new password",
savePassword: "Save new password",
savingPassword: "Saving…",
passwordTooShort: "New password must be at least 6 characters",
passwordTooShort: "New password must be at least 8 characters",
passwordMismatch: "New passwords do not match",
passwordMustChange: "New password must differ from the default/old password",
},