Skip to content

feat(auth): implement token revocation via Redis blacklist [REN-72] - #113

Merged
Scott Graham (cheddarfox) merged 1 commit into
devfrom
REN-72-token-revocation
Mar 9, 2026
Merged

Scott Graham (cheddarfox) merged 1 commit into
devfrom
REN-72-token-revocation

Conversation

@cheddarfox

Copy link
Copy Markdown
Member

Summary

  • Add TokenBlacklist service (core/auth/blacklist.py) with Redis-backed revoke() and is_revoked() — fail-open design
  • Add jti (JWT ID) claim to all tokens for unique identification
  • Make verify_token() async with blacklist check before returning valid payload
  • Replace placeholder logout endpoint with actual token revocation
  • Update all callers of verify_token() (auth middleware, refresh endpoint, test suite)
  • 7 tests covering revocation, fail-open, verify rejection, and HTTP logout integration

Test plan

  • test_revoke_token_adds_to_blacklist — revoke sets Redis key with TTL
  • test_is_revoked_returns_false_for_unknown — non-revoked JTI → False
  • test_revoke_expired_token_skips — already-expired token skips Redis
  • test_blacklist_fail_open_revoke — Redis down → returns False
  • test_blacklist_fail_open_check — Redis down → returns False
  • test_verify_token_rejects_revoked — blacklisted token raises HTTPException
  • test_logout_revokes_token — POST /auth/logout blacklists the Bearer token

🤖 Generated with Claude Code

Add Redis-backed JWT token blacklist for secure logout. Tokens now
include a jti (JWT ID) claim, and verify_token checks the blacklist
before accepting any token. The blacklist uses fail-open semantics
so Redis unavailability does not block authentication.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@cheddarfox
Scott Graham (cheddarfox) merged commit 5b3337f into dev Mar 9, 2026
11 of 13 checks passed
@cheddarfox
Scott Graham (cheddarfox) deleted the REN-72-token-revocation branch March 9, 2026 23:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant