chat-ui
f0c4e76b - feat(mcp): encrypt OAuth credentials at rest and expire idle connections

Commit
53 days ago
feat(mcp): encrypt OAuth credentials at rest and expire idle connections A1 — encrypt the secret fields of an OAuth connection (access/refresh/id tokens, client secret, PKCE verifier) with AES-256-GCM keyed by MCP_OAUTH_ENCRYPTION_KEY. Metadata (expiry, scope, client_id, CSRF state) stays plaintext so projections and lookups are unchanged. Values are tagged 'enc.v1:'; decryption passes through untagged legacy plaintext, so existing records migrate lazily on rewrite and an unset key keeps today's plaintext behavior (with a startup warning). Encrypt on write, decrypt at point-of-use; the redundant tokens.refresh_token match in the refresh path is dropped in favor of the version guard. B1 — authenticated connections get a 90-day sliding idle TTL (previously none), refreshed on each use via the existing deleteAt TTL index, so abandoned grants don't persist forever. Adds crypto round-trip tests and documents MCP_OAUTH_ENCRYPTION_KEY in .env.
Author
Parents
Loading