feat(config): publish a concurrent session limit - #54
Merged
Conversation
max_concurrent_sessions says how many sessions one user may hold at once. null means no limit, and that is the default, so a deployment predating the key keeps behaving exactly as it does now. null rather than 0 for unlimited. Zero would otherwise read as "no sessions allowed", which is a plausible way for an operator to try to remove a cap and lock every user out instead. The schema refuses zero, and any negative or fractional value, on both the full config and a patch. This is NIST 800-53 AC-10, concurrent session control, and an operational concern wherever workstations are shared, since an unbounded count leaves sessions alive on machines a user has walked away from. This publishes the key only. Enforcing it belongs to the consuming server. Refs fells-code/seamless-auth-api#176
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Publishes the config key that
seamless-auth-api#176needs. Enforcement is theserver's job and lands separately; this is the shared shape only.
The key
How many sessions one user may hold at once.
nullmeans no limit and is thedefault, so a deployment that predates the key behaves exactly as it does today.
nullrather than0for unlimited. Zero would otherwise read as "no sessionsallowed", which is a plausible way for an operator to try to remove a cap and
lock every user out instead. The schema refuses zero, and any negative or
fractional value, on both
SystemConfigSchemaandSystemConfigPatchSchema.Why
NIST 800-53 AC-10, concurrent session control, which is a standard question in a
government security review. It is also an operational concern wherever
workstations are shared, since an unbounded session count leaves sessions alive
on machines a user has walked away from.
Consumers
Additive and defaulted, so nothing breaks. The API will read it to decide when to
evict; the admin dashboard gets the key for free once it picks up the release.
npm run typecheck,npm run lint,npm run format:check,npm run buildandnpm testall pass (218 tests, 16 files), and the builtdistcarries the key onall three schemas.