MCPcopy Create free account
hub / github.com/boringstack-xyz/boringstack / revokeAllForUser

Function revokeAllForUser

apps/api/src/lib/jwt/jwt-revocation.ts:67–81  ·  view source on GitHub ↗
(userId: string)

Source from the content-addressed store, hash-verified

65 * attacker racing the call).
66 */
67const revokeAllForUser = async (userId: string): Promise<void> => {
68 const cutoffSeconds = Math.floor(nowMs() / 1000) + 1;
69
70 try {
71 await cacheService.set(userRevokeKey(userId), cutoffSeconds, {
72 ttlSeconds: USER_REVOKE_TTL_SECONDS,
73 });
74 } catch (error: unknown) {
75 logger.warn("Failed to revoke all JWTs for user", {
76 event: "auth.jwt.revoke_user_failed",
77 userId,
78 error: getErrorMessage(error),
79 });
80 }
81};
82
83/**
84 * Whether the given JTI has been blocklisted. On cache errors the

Callers

nothing calls this directly

Calls 5

nowMsFunction · 0.90
getErrorMessageFunction · 0.90
userRevokeKeyFunction · 0.85
warnMethod · 0.80
setMethod · 0.45

Tested by

no test coverage detected