Skip to content

Commit 9f4d012

Browse files
dcramerclaude
andauthored
fix(cloudflare): Set KV lock TTL to 60s minimum required by Cloudflare (#784)
## Summary - Cloudflare KV requires `expirationTtl` >= 60 seconds, but the OAuth refresh lock TTL was set to 30s - Every OAuth token refresh was failing with `KV PUT failed: 400 Invalid expiration_ttl of 30` - 332 occurrences affecting 42 users since the lock was introduced in #778 ## Changes - Bumped `LOCK_TTL_SECONDS` from 30 to 60 - Added comment documenting the Cloudflare KV minimum - Updated test assertion Fixes MCP-SERVER-F2H Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
1 parent a74b685 commit 9f4d012

2 files changed

Lines changed: 3 additions & 2 deletions

File tree

‎packages/mcp-cloudflare/src/server/oauth/helpers.test.ts‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -219,7 +219,7 @@ describe("tokenExchangeCallback", () => {
219219
expect(mockKV.put).toHaveBeenCalledWith(
220220
"refresh-lock:user-id",
221221
expect.any(String),
222-
expect.objectContaining({ expirationTtl: 30 }),
222+
expect.objectContaining({ expirationTtl: 60 }),
223223
);
224224
expect(mockKV.delete).toHaveBeenCalledWith("refresh-lock:user-id");
225225
});

‎packages/mcp-cloudflare/src/server/oauth/helpers.ts‎

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -217,7 +217,8 @@ export async function refreshAccessToken({
217217
// with the same refresh token, the first wins and the second gets
218218
// invalid_grant. The lock + result cache ensures only one isolate refreshes
219219
// per user; others wait and reuse the cached result.
220-
const LOCK_TTL_SECONDS = 30;
220+
// NOTE: Cloudflare KV requires expirationTtl >= 60 seconds.
221+
const LOCK_TTL_SECONDS = 60;
221222
const RESULT_TTL_SECONDS = 60;
222223
const LOCK_WAIT_MS = 2000;
223224

0 commit comments

Comments
 (0)