mirror of
https://github.com/ZHANGTIANYAO1/teamspeak-music-bot.git
synced 2026-10-02 13:02:49 +08:00
fix(guest): cap guest session TTL on touch
The sliding-refresh branch in validateAndTouch hardcoded SESSION_TTL_MS (7d) for all roles, so a guest session created with GUEST_SESSION_TTL_MS (1d) was wrongly bumped to 7d on the first touch after the touch interval. Derive the touch TTL from row.role instead. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
1 parent
66230e6b43
commit
c1d73b6ba8
2 files changed
+40
-1
No files matched your search
@@ -83,7 +83,10 @@ export function createSessionStore(db: Database.Database): SessionStore {
|
||||
return null;
|
||||
}
|
||||
if (now - row.lastSeenAt > SESSION_TOUCH_INTERVAL_MS) {
|
||||
touchStmt.run(now, now + SESSION_TTL_MS, id);
|
||||
// Refresh against the role's own TTL — guests are short-lived (1d) and
|
||||
// must NOT be bumped to the member/admin 7d window on touch.
|
||||
const ttl = row.role === "guest" ? GUEST_SESSION_TTL_MS : SESSION_TTL_MS;
|
||||
touchStmt.run(now, now + ttl, id);
|
||||
}
|
||||
return { userId: row.userId, username: row.username, role: row.role as "admin" | "member" | "guest" };
|
||||
},
|
||||
|
||||
Reference in new issue
Block a user