Skip to content

fix(models): exclude oauth client sessions from mfa step-up invalidation (#2801) - #2802

Open
melcheikh wants to merge 2 commits into
supabase:masterfrom
melcheikh:fix/preserve-oauth-sessions-on-mfa-invalidation
Open

melcheikh wants to merge 2 commits into
supabase:masterfrom
melcheikh:fix/preserve-oauth-sessions-on-mfa-invalidation

Conversation

@melcheikh

Copy link
Copy Markdown

What kind of change does this PR introduce?

Bug fix.

What is the current behavior?

Closes #2801.

When a user completes an MFA verification (verifyTOTPFactor, verifyPhoneFactor, verifyWebAuthnFactor, or RecoveryCodesVerify), GoTrue calls models.InvalidateSessionsWithAALLessThan(tx, user.ID, models.AAL2.String()).

The function executes:

DELETE FROM sessions WHERE user_id = ? AND aal < ?

Because OAuth 2.1 client sessions are issued at AAL1 and cannot step up to AAL2, any MFA verification by the user deletes all sessions issued to third-party OAuth clients. Subsequent refresh attempts by those clients fail with refresh_token_not_found.

What is the new behavior?

InvalidateSessionsWithAALLessThan now excludes sessions associated with an OAuth client:

DELETE FROM sessions WHERE user_id = ? AND aal < ? AND oauth_client_id IS NULL

OAuth client session lifecycles remain managed by consent revocation via RevokeOAuthSessions.

Additional context

Added unit test TestInvalidateSessionsWithAALLessThan_PreservesOAuthSessions in internal/models/sessions_test.go. The test asserts that:

  1. Standard browser AAL1 sessions are invalidated on step-up.
  2. OAuth client sessions (oauth_client_id present) are preserved.
  3. Higher-assurance AAL2 sessions are preserved.

@melcheikh
melcheikh requested a review from a team as a code owner September 14, 2026 04:32

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

OAuth 2.1 server: MFA verification deletes OAuth client sessions (InvalidateSessionsWithAALLessThan does not exclude oauth_client_id)

1 participant