fix(action-token): make link reservations wallet-scoped, atomic and self-healing - #581
Merged
mahdi2ba merged 1 commit intoSep 21, 2026
Conversation
…elf-healing Follow-ups to Greenstand#579 (Greenstand#574), from its review. - generate() flags the tokens and inserts the link row in one transaction. A short reservation (a concurrent link or send got there first) or a failed insert rolls the flags back, so no token can stay flagged for a link that does not exist. The UPDATE is also scoped to the sender wallet. - Explicit token ids must belong to the sender wallet. walletB could name a token of walletC, a wallet it manages, without sender_wallet; the link then spoke for walletB and claim time refused it forever. Refuse at generate time, to the sender, with a clear message. - Housekeeping releases every token flagged for a link that is not active, in one statement (NOT EXISTS active row), instead of a per-id loop after expiry. That also heals whatever a crash between two statements left behind. cancel() updates state and releases in one transaction. - New migration turns token_action_token_id_idx into a partial index on action_token_id IS NOT NULL: nearly every row is NULL, so the index stays tiny and off the write path of ordinary token updates. - GET /action-tokens?state=expired is accepted; rows can be expired since Greenstand#579. Three integration specs: an explicit token of a managed wallet without sender_wallet is refused and flags nothing; a token flagged for a link with no row is released on the next link activity; expired links list by state. Refs Greenstand#574 Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
|
🎉 This PR is included in version 1.44.0-keycloak.32 🎉 The release is available on GitHub release Your semantic-release bot 📦🚀 |
5 of 6 tasks
Collaborator
|
@mahdi2ba because we won't change the action token system, so this is not needed, right? |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Follow-ups to #579 from its review, verified one by one against the merged code.
Three integration specs added to actiontoken-reservation.spec.js.
Refs #574