{"record":{"id":"dc8b08959c405bb2","repo":"toeverything/AFFiNE","slug":"auth-session-expired","errorCode":"AUTH_SESSION_EXPIRED","errorMessage":"AUTH_SESSION_EXPIRED","messagePattern":"AUTH_SESSION_EXPIRED","errorType":"error_code","errorClass":"SessionAccessTokenError","httpStatus":401,"severity":"error","filePath":"packages/backend/server/src/core/auth/access-token.ts","lineNumber":104,"sourceCode":"    const { authSessionId, userId } = verified;\n    if (!authSessionId || !userId) {\n      throw new SessionAccessTokenError('ACCESS_TOKEN_INVALID');\n    }\n    const authSession = await this.models.authSession.get(authSessionId);\n    if (!authSession || authSession.userSession.userId !== userId) {\n      throw new SessionAccessTokenError('ACCESS_TOKEN_INVALID');\n    }\n    if (authSession.revokedAt) {\n      throw new SessionAccessTokenError('AUTH_SESSION_REVOKED');\n    }\n    const now = new Date();\n    if (\n      authSession.idleExpiresAt <= now ||\n      authSession.absoluteExpiresAt <= now ||\n      (authSession.userSession.expiresAt &&\n        authSession.userSession.expiresAt <= now)\n    ) {\n      throw new SessionAccessTokenError('AUTH_SESSION_EXPIRED');\n    }\n    const user = await this.models.user.get(userId);\n    if (!user || user.disabled) {\n      throw new SessionAccessTokenError('AUTH_SESSION_REVOKED');\n    }\n    return {\n      ...authSession.userSession,\n      authSessionId: authSession.id,\n      authenticatedAt: authSession.createdAt,\n      user: sessionUser(user) as CurrentUser,\n    };\n  }\n}\n","sourceCodeStart":86,"sourceCodeEnd":118,"githubUrl":"https://github.com/toeverything/AFFiNE/blob/b4c8548c09da21b2898443559a5b846f0ccf5dd8/packages/backend/server/src/core/auth/access-token.ts#L86-L118","documentation":"verify throws AUTH_SESSION_EXPIRED when the session record's idle or absolute expiry time has passed, meaning a valid token belongs to a session the server no longer accepts; the client must re-authenticate.","triggerScenarios":"Thrown at packages/backend/server/src/core/auth/access-token.ts:104 when the library encounters an invalid state.","commonSituations":"See trigger scenarios.","solutions":["The auth session's expiry time has passed — sign in again; expired sessions cannot be refreshed.","If this happens too quickly, check the server's session TTL configuration (auth.session.ttl) and the server clock."],"exampleFix":"// Server config: extend session lifetime if sessions expire too soon\nauth:\n  session:\n    ttl: '30d'\n// Client: on AUTH_SESSION_EXPIRED, redirect to sign-in.","handlingStrategy":"validation","validationCode":null,"typeGuard":null,"tryCatchPattern":null,"preventionTips":[],"tags":[],"backgroundTag":null,"analyzedSha":"b4c8548c09da21b2898443559a5b846f0ccf5dd8","analyzedAt":"2026-08-18T21:16:52.546Z","contentChangedAt":"2026-08-18T21:16:52.546Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}