How to use this reference
Editorial lesson: model revocation as a shared invariant across every transport. The advisory identifies 0.10.0 as patched through shared revocation checks. Distinguish denial of new connections from termination of existing ones when reviewing remediation guarantees.
Before reading
- JWT validity, session revocation and asynchronous transports
Context and limits
- Applies to Redis-backed versions 0.9.0 through versions before 0.10.0 and requires possession of an otherwise valid revoked token. Without Redis, per-token invalidation is unsupported by design.
- Realtime disclosure and impersonation are maintainer-described consequences; broader production exploitation is not established. Terminal access additionally depends on terminal configuration; HTTP remains protected.
- Existing-connection termination is not established. The advisory identifies doge-woof as the publishing account and credits huslayer826 as Reporter and Classic298 as Coordinator. The reviewed advisory provides no explicit article byline; these publication and credit roles do not establish article authorship. Separate from the catalog's role-claim provenance advisory.
Sources and provenance
- Realtime endpoints accept Redis-revoked JWTs after signout/backchannel logout Open WebUI · reviewed 2026-10-03
Record reviewed 2026-10-03. Snapshot 53796974ace8. Open the complete JSON contract.