Skip to content

fix condition for db tokens invalidation support - #1064

Open
sivukhin wants to merge 2 commits into
mainfrom
fix-db-tokens-invalidation
Open

sivukhin wants to merge 2 commits into
mainfrom
fix-db-tokens-invalidation

Conversation

@sivukhin

Copy link
Copy Markdown
Contributor

turso-server support db tokens invalidation

@pedrocarlo pedrocarlo mentioned this pull request Sep 28, 2026
2 tasks done
pedrocarlo added a commit that referenced this pull request Sep 28, 2026
## Summary
- Route `turso db tokens invalidate <database>` to the database-scoped
rotation endpoint for grouped as well as ungrouped databases, rather
than refusing grouped databases or substituting group rotation.
- Correct the database confirmation: database-scoped tokens need
replacement; group tokens are unaffected. Do not claim replica restarts
or downtime.
- Clarify `turso group tokens invalidate` help, confirmation, and
success output: this invalidates group tokens but not necessarily
database-scoped tokens. To revoke the latter, run `turso db tokens
invalidate <database-name>` for each database. Avoid claiming all
database connections drop or that downtime occurs.
- Add command-level and endpoint tests for grouped databases and the
legacy dedicated-cluster error.

## Testing
- [x] `go test ./... -count=1`
- [x] `git diff --check`

## Caveat
Legacy dedicated grouped clusters reject individual database credential
rotation (HTTP 400). The CLI propagates that error without silently
rotating group credentials. Their group rotation can affect database
tokens through a shared cluster key, which is why the guidance says "not
necessarily".

Related: #1064 touches the same command with a server-type gate; this PR
uses the database endpoint as the source of support instead.

Amp thread:
https://ampcode.com/threads/T-01a0e943-2130-70ed-8b52-4fb27500934a

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants