Skip to content

JWT secret not rotated / no key rollover mechanism #489

Description

@DeFiVC

What

The application has no mechanism to rotate the JWT signing key without invalidating all existing tokens.

Why

If the JWT secret is compromised (leaked, exposed in logs, etc.), there is no way to:

  1. Issue new tokens with a new key while allowing old tokens to expire naturally
  2. Support multiple active signing keys during a rotation window
  3. Gracefully transition between keys

This means a key compromise requires either:

  • Immediate invalidation of ALL user sessions (bad UX)
  • Continuing to use a compromised key (security risk)

Scope

  • Support an array of JWT secrets (current + previous)
  • Verify tokens against all active secrets
  • Sign new tokens only with the latest secret
  • Add a configuration option for key rotation (JWT_SECRET_PREVIOUS)
  • Document the rotation procedure

Acceptance Criteria

  • Multiple JWT secrets can be configured
  • Token verification checks all configured secrets
  • New tokens are signed with the latest secret
  • Graceful transition when adding a new key

Technical Context

  • File: src/server.ts:184-187 (JWT registration)
  • Fastify JWT supports verify with multiple secrets via an array
  • Config: JWT_SECRET (current), JWT_SECRET_PREVIOUS (optional)

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

Stellar WaveIssues in the Stellar wave programenhancementNew feature or requesthigh

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions