#100 FTX-100: last_used_at is never written — the API reports a permanently-null field operators use to triage keys

closed medium bug Created 2026-07-31 18:29 · Updated 2026-07-31 18:30

Description

Edit
EARS SPEC: - When an API key successfully authenticates a request, Futex shall record the time of use on that key. - The Futex API key listings shall report a last_used_at that reflects actual use. - If the last-used bookkeeping write fails, then authentication shall still succeed. CAUSE: app/models.py declares ApiKey.last_used_at and app/main.py returns it in both the tenant and platform key listings, but no code path ever assigns it. It is NULL for every key ever issued. WHY IT MATTERS: an operator deciding which of several platform-admin keys is safe to revoke has exactly one signal in the API, and it is dead. Worse, it reads as 'never used' for a key that IS in use — inviting revocation of the only working credential. Found while triaging 10 active platform-admin keys on prod (9 minted by an audit-harness run on 2026-07-30).

Comments

Loading comments...

Context

Loading context...

Audit History

View All
Loading audit history...