server: user auth tokens valid 180 days (was PocketBase default 5)
Phone sync broke 2026-09-17 with HTTP 400: its 5-day token had expired and the app never refreshes it, so writes arrived anonymous and the rules rejected them. User chose 180 days. App-side refresh follows in wave 11. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
1 parent
3c30a20324
commit
ab1d294657
1 file changed
+16
@@ -0,0 +1,16 @@
|
||||
/// <reference path="../pb_data/types.d.ts" />
|
||||
// 2026-09-17: user auth tokens were valid for PocketBase's default 5 days
|
||||
// (432000s), and the app never refreshed them, so a phone that went five days
|
||||
// without logging in again started syncing anonymously. The rules turned every
|
||||
// write away (POST 400 "create rule failure", PATCH 404). Two users on a private
|
||||
// server gain nothing from short-lived tokens, so the user chose 180 days.
|
||||
// The app also refreshes the token on every sync; this is the backstop.
|
||||
migrate((app) => {
|
||||
const collection = app.findCollectionByNameOrId("_pb_users_auth_")
|
||||
collection.authToken.duration = 15552000 // 180 days
|
||||
return app.save(collection)
|
||||
}, (app) => {
|
||||
const collection = app.findCollectionByNameOrId("_pb_users_auth_")
|
||||
collection.authToken.duration = 432000 // PocketBase default, 5 days
|
||||
return app.save(collection)
|
||||
})
|
||||
Reference in new issue
Block a user