diff --git a/server/pb_migrations/1789608448_users_token_duration_180d.js b/server/pb_migrations/1789608448_users_token_duration_180d.js new file mode 100644 index 0000000..29f99d0 --- /dev/null +++ b/server/pb_migrations/1789608448_users_token_duration_180d.js @@ -0,0 +1,16 @@ +/// +// 2026-09-17: user auth tokens were valid for PocketBase's default 5 days +// (432000s), and the app never refreshed them, so a phone that went five days +// without logging in again started syncing anonymously. The rules turned every +// write away (POST 400 "create rule failure", PATCH 404). Two users on a private +// server gain nothing from short-lived tokens, so the user chose 180 days. +// The app also refreshes the token on every sync; this is the backstop. +migrate((app) => { + const collection = app.findCollectionByNameOrId("_pb_users_auth_") + collection.authToken.duration = 15552000 // 180 days + return app.save(collection) +}, (app) => { + const collection = app.findCollectionByNameOrId("_pb_users_auth_") + collection.authToken.duration = 432000 // PocketBase default, 5 days + return app.save(collection) +})