From ab1d294657df4b9b4327f0f2455066c36854f8db Mon Sep 17 00:00:00 2001 From: Sprite Date: Thu, 17 Sep 2026 01:28:12 +0000 Subject: [PATCH] server: user auth tokens valid 180 days (was PocketBase default 5) Phone sync broke 2026-09-17 with HTTP 400: its 5-day token had expired and the app never refreshes it, so writes arrived anonymous and the rules rejected them. User chose 180 days. App-side refresh follows in wave 11. Co-Authored-By: Claude Opus 5 --- .../1789608448_users_token_duration_180d.js | 16 ++++++++++++++++ 1 file changed, 16 insertions(+) create mode 100644 server/pb_migrations/1789608448_users_token_duration_180d.js diff --git a/server/pb_migrations/1789608448_users_token_duration_180d.js b/server/pb_migrations/1789608448_users_token_duration_180d.js new file mode 100644 index 0000000..29f99d0 --- /dev/null +++ b/server/pb_migrations/1789608448_users_token_duration_180d.js @@ -0,0 +1,16 @@ +/// +// 2026-09-17: user auth tokens were valid for PocketBase's default 5 days +// (432000s), and the app never refreshed them, so a phone that went five days +// without logging in again started syncing anonymously. The rules turned every +// write away (POST 400 "create rule failure", PATCH 404). Two users on a private +// server gain nothing from short-lived tokens, so the user chose 180 days. +// The app also refreshes the token on every sync; this is the backstop. +migrate((app) => { + const collection = app.findCollectionByNameOrId("_pb_users_auth_") + collection.authToken.duration = 15552000 // 180 days + return app.save(collection) +}, (app) => { + const collection = app.findCollectionByNameOrId("_pb_users_auth_") + collection.authToken.duration = 432000 // PocketBase default, 5 days + return app.save(collection) +})