Relationships
#2413 serve: ServerTokenGcService is never started, so expired server tokens accumulate forever
Opened by hammz · 9/23/2026· Shipped 9/25/2026
Description
swamp serve never starts ServerTokenGcService, so expired and revoked OAuth server tokens are never cleaned up. swamp-club#1614 asked for a periodic GC sweep in serve and is marked shipped. PR #2130 (commit d8225862, 2026-08-12) added src/serve/server_token_gc_service.ts and its test, but nothing constructs or starts the service. ServerTokenGcService has no references outside its own file and test, and git log -S ServerTokenGcService shows it was never wired into src/cli/commands/serve.ts and later removed.
Impact
Every swamp auth server-login against an OAuth-mode server mints a new oauth-<random> token. Each token adds an auto-definition, a data partition, a token secret and an OAuth access token, and all four stay forever, which is the unbounded growth #1614 set out to stop.
That growth also slows the login path itself (swamp-club#2408):
- A full-walk
pushChangedrebuilds the index from every shard, so every leftover token partition makes each such push slower. - The mint's
defRepo.findByNameand its definition read-back parse every server-token definition, so they slow down linearly with the number of tokens.
Steps to reproduce
- Run
swamp servein OAuth mode. - Log in with
swamp auth server-loginseveral times. .swamp/auto-definitions/swamp/server-token/gains one definition per login, and noStarting server token GC servicelog line ever appears.
Expected
Serve starts the GC service at boot, after token secret migration, as #1614 specified. It runs on its interval and deletes expired and revoked tokens after the grace period.
Shipped
Click a lifecycle step above to view its details.
Sign in to post a ripple.