Expired session cookie still grants access to protected Server Action
0 reputation · 12 Jan 2021, 02:31 UTC
Goal: Confirm that an expired session cookie is rejected both by the Middleware optimistic check and by the Data Access Layer authorization so that a protected Server Action cannot be invoked with stale credentials, enforcing least‑privilege access.
Constraint: Middleware runs in the Edge runtime where Node‑only APIs are unavailable and response mutation for downstream server code is unreliable, making token refresh there difficult; the DAL can validate and refresh tokens accurately but may duplicate logic across Server Actions. Uncertainty remains about the optimal placement of token refresh logic to avoid duplication while preserving security.
- Should token refresh be performed in Middleware despite its limited Node APIs, or delegated to the DAL per request?
- How can a refreshed token be made available to downstream Server Actions without re‑implementing validation logic?
- What caching safeguards are needed when token refresh occurs in the DAL to prevent serving stale authorized responses?