Phone sync broke 2026-09-17 with HTTP 400: its 5-day token had expired and the app never refreshes it, so writes arrived anonymous and the rules rejected them. User chose 180 days. App-side refresh follows in wave 11. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
17 lines
872 B
JavaScript
17 lines
872 B
JavaScript
/// <reference path="../pb_data/types.d.ts" />
|
|
// 2026-09-17: user auth tokens were valid for PocketBase's default 5 days
|
|
// (432000s), and the app never refreshed them, so a phone that went five days
|
|
// without logging in again started syncing anonymously. The rules turned every
|
|
// write away (POST 400 "create rule failure", PATCH 404). Two users on a private
|
|
// server gain nothing from short-lived tokens, so the user chose 180 days.
|
|
// The app also refreshes the token on every sync; this is the backstop.
|
|
migrate((app) => {
|
|
const collection = app.findCollectionByNameOrId("_pb_users_auth_")
|
|
collection.authToken.duration = 15552000 // 180 days
|
|
return app.save(collection)
|
|
}, (app) => {
|
|
const collection = app.findCollectionByNameOrId("_pb_users_auth_")
|
|
collection.authToken.duration = 432000 // PocketBase default, 5 days
|
|
return app.save(collection)
|
|
})
|