Repository navigation
Conversation
last_challenged_at is a per-factor timestamp, but the column was created with a global unique constraint: when factors of two different users are challenged within the same microsecond, the second challenge fails with a 500 (duplicate key value violates unique constraint "mfa_factors_last_challenged_at_key"). Drop the constraint (idempotent) and add a model test showing two factors can record the same last_challenged_at. Fixes supabase#2854 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
last_challenged_at is a per-factor timestamp, but the column was created with a global unique constraint: when factors of two different users are challenged within the same microsecond, the second challenge fails with a 500 (duplicate key value violates unique constraint "mfa_factors_last_challenged_at_key").
Drop the constraint (idempotent) and add a model test showing two factors can record the same last_challenged_at.
Fixes #2854
What kind of change does this PR introduce?
Bug fix
What is the current behavior?
Migration
20240802193726_add_mfa_factors_column_last_challenged_atdeclareslast_challenged_at timestamptz unique. The column stores the time of afactor's latest challenge, so the constraint is global across all users: when
two users' factors are challenged within the same microsecond,
Factor.WriteChallengeToDatabasefails on the secondUpdateOnlyandPOST /factors/{id}/challengereturns a 500(
duplicate key value violates unique constraint "mfa_factors_last_challenged_at_key").We hit it in our end-to-end test suite, which runs TOTP sign-ins
concurrently: valid requests occasionally fail with a 500, and the only
client-side remedy is to retry the challenge. #2854 measured about 2.5 %
failures with 20 concurrent users.
Nothing in the code relies on uniqueness:
last_challenged_atis only readfor the phone MFA send-frequency check (
internal/api/mfa.go), per factor.What is the new behavior?
drop constraint if existskeeps it idempotent and safe on projects wherethe constraint was already removed manually.
last_challenged_at.No API or behaviour change other than the 500 disappearing.
Additional context
Reproduced the CI job locally (Go 1.27.0,
CGO_ENABLED=1,postgres:15with
hack/init_postgres.sql,make migrate_dev, thenmake test):TestFactor/TestFactorsCanShareLastChallengedAtfails with
duplicate key value violates unique constraint "mfa_factors_last_challenged_at_key" (SQLSTATE 23505).-race.make check-format,go vet,staticcheckandgosecpass.Note:
make vulncheckcurrently reports GO-2026-6505 ingo.opentelemetry.io/otelv1.44.0 (fixed in v1.45.0). It is unrelated tothis change (no dependency is modified) and should fail the same way on
master; the OpenTelemetry bump to v1.45.0 already seems to be in progressupstream, so I left it out of this PR.