Skip to content

feat(auth): add session anomaly detection and forced logout (#515) - #542

Open
Gezziy wants to merge 2 commits into
Neurowealth:mainfrom
Gezziy:anomaly-detection
Open

Gezziy wants to merge 2 commits into
Neurowealth:mainfrom
Gezziy:anomaly-detection

Conversation

@Gezziy

@Gezziy Gezziy commented Sep 28, 2026

Copy link
Copy Markdown

closes #515

Summary of Changes
Anomaly Detection Service (src/services/session-anomaly.service.ts):
Implemented detectSessionAnomaly evaluating three $O(1)$ heuristics: IMPOSSIBLE_LOCATION_HOP (location hop in < 15 mins), SUSPICIOUS_DEVICE_TYPE_CHANGE (mid-session shift to CLI or mismatched mobile OS), and SUBNET_JUMP_ANOMALY (IP jump across /16 subnets in < 60s).
Implemented evaluateAndHandleSessionAnomaly to execute session revocation, immediate WebSocket disconnection (closeUserSockets), and security event emission.

Middleware & Token Rotation Integration:
Updated requireAuth (
src/middleware/authenticate.ts
) to intercept suspicious requests with 401 Unauthorized (session_anomaly_detected).
Updated rotateRefreshToken (

src/services/refresh-token.service.ts
) to validate session context during token refresh.
Event Vocabulary (src/events/types.ts):
Registered security.session_anomaly under SOCKET_ONLY_EVENT_TYPES mapped to the alerts topic.

Unit Test Coverage (tests/unit/session-anomaly.test.ts):
Added unit test suite covering heuristic evaluations and forced logout flows.

Reason for Changes
To fulfill Issue #515, enhancing account security and mitigating risk of Session Hijacking and Account Takeover (ATO). Suspicious session activities now trigger immediate, standardized protective controls and security audit events.

…lth#515)

- Implement session anomaly service with location hop, device mutation, and subnet jump heuristics
- Integrate anomaly evaluation into requireAuth middleware and rotateRefreshToken service
- Trigger automatic session revocation, WebSocket termination, and security.session_anomaly event
- Add comprehensive unit tests covering heuristics and protective workflows
@drips-wave

drips-wave Bot commented Sep 28, 2026

Copy link
Copy Markdown

@Gezziy Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits.

You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀

Learn more about application limits

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Add session anomaly detection and forced logout for suspicious activity

1 participant