p0-h3-access-token-blacklist-race

donetype/backlogpriority/p0severity/hightopic/auth

p0 路 H3 路 Access-token blacklist on auto-rotate is racy

TL;DR

Moot after Phase A: bespoke rotating refresh / tokenBlacklist removed with Auth.js migration (d5b94ce). Race no longer exists.

Status: done (2026-05-18) 路 Source: [[Projects/personal-finance-notion/context/audit-2026-05-17-auth|Auth audit 2026-05-17 搂H3]]

Entire src/lib/auth.ts rotating-refresh path replaced by Auth.js shim. tokenBlacklist.ts and refreshTokenSessionModel.ts deleted.

Spun out

None.

Related

  • [[Projects/personal-finance-notion/backlog/done/p0-authjs-phase-a-foundation|Phase A]]