Skip to content

feat: use personal access tokens for long-lived auth - #7

Merged
mooncitizen merged 2 commits into
mainfrom
feat/personal-access-tokens
Apr 8, 2026
Merged

mooncitizen merged 2 commits into
mainfrom
feat/personal-access-tokens

Conversation

@mooncitizen

Copy link
Copy Markdown
Contributor

Summary

Exchange short-lived Supabase JWT for a long-lived PAT after OAuth login. PATs never expire unless revoked, fixing the 1-hour logout issue.

Changes

  • Add pat field to Credentials with backward-compatible serde defaults
  • Exchange Supabase tokens for PAT via POST /tokens/cli after OAuth
  • Use PAT in Authorization header when available
  • Skip token refresh logic when using PAT
  • On 401 with PAT, clear credentials and prompt re-login
  • Fix TOKEN_LIFETIME to 3600s (was incorrectly 28800s)
  • Add rust-analyzer to nix dev shell

How to test

  • Login
  • Wait > 1 hour access the application

Checklist

  • Code compiles without warnings (cargo build --workspace)
  • Tests pass (cargo test --workspace)
  • I have tested this on my platform (macOS / Linux)

Exchange short-lived Supabase JWT for a long-lived PAT after OAuth login.
PATs never expire unless revoked, fixing the 1-hour logout issue.

- Add pat field to Credentials with backward-compatible serde defaults
- Exchange Supabase tokens for PAT via POST /tokens/cli after OAuth
- Use PAT in Authorization header when available
- Skip token refresh logic when using PAT
- On 401 with PAT, clear credentials and prompt re-login
- Fix TOKEN_LIFETIME to 3600s (was incorrectly 28800s)
- Add rust-analyzer to nix dev shell
@mooncitizen
mooncitizen merged commit f59a54f into main Apr 8, 2026
2 checks passed
@mooncitizen
mooncitizen deleted the feat/personal-access-tokens branch April 8, 2026 21:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant