toeverything/AFFiNE · error · SessionAccessTokenError

AUTH_SESSION_EXPIRED

AUTH_SESSION_EXPIRED

Error message

AUTH_SESSION_EXPIRED

What it means

verify throws AUTH_SESSION_EXPIRED when the session record's idle or absolute expiry time has passed, meaning a valid token belongs to a session the server no longer accepts; the client must re-authenticate.

Solutions

  1. The auth session's expiry time has passed — sign in again; expired sessions cannot be refreshed.
  2. If this happens too quickly, check the server's session TTL configuration (auth.session.ttl) and the server clock.

Example fix

// Server config: extend session lifetime if sessions expire too soon
auth:
  session:
    ttl: '30d'
// Client: on AUTH_SESSION_EXPIRED, redirect to sign-in.
Defensive patterns

Strategy: validation

When it happens

Trigger: Thrown at packages/backend/server/src/core/auth/access-token.ts:104 when the library encounters an invalid state.

Common situations: See trigger scenarios.


AI-assisted analysis of toeverything/AFFiNE@b4c8548c09 (2026-08-18). Data as JSON: /api/errors/dc8b08959c405bb2. Report an issue: GitHub.

Appendix: source

Thrown at packages/backend/server/src/core/auth/access-token.ts:104

    const { authSessionId, userId } = verified;
    if (!authSessionId || !userId) {
      throw new SessionAccessTokenError('ACCESS_TOKEN_INVALID');
    }
    const authSession = await this.models.authSession.get(authSessionId);
    if (!authSession || authSession.userSession.userId !== userId) {
      throw new SessionAccessTokenError('ACCESS_TOKEN_INVALID');
    }
    if (authSession.revokedAt) {
      throw new SessionAccessTokenError('AUTH_SESSION_REVOKED');
    }
    const now = new Date();
    if (
      authSession.idleExpiresAt <= now ||
      authSession.absoluteExpiresAt <= now ||
      (authSession.userSession.expiresAt &&
        authSession.userSession.expiresAt <= now)
    ) {
      throw new SessionAccessTokenError('AUTH_SESSION_EXPIRED');
    }
    const user = await this.models.user.get(userId);
    if (!user || user.disabled) {
      throw new SessionAccessTokenError('AUTH_SESSION_REVOKED');
    }
    return {
      ...authSession.userSession,
      authSessionId: authSession.id,
      authenticatedAt: authSession.createdAt,
      user: sessionUser(user) as CurrentUser,
    };
  }
}

View on GitHub (pinned to b4c8548c09)