Security, Governance and Platform · Principal
The user's access was revoked. Why is their open answer stream still revealing the document?
Take a few minutes to form your approach. Then open a worked answer and compare the decisions.
Reveal a worked answer
The request was authorized when it opened. The server retrieved a permitted document, put it in model context and started streaming tokens. Then an administrator removed access. That does not undo the authorization decision already made or pull bytes back from a response in progress. If the stream simply runs to completion, the user can still receive text derived from that document. Revoking an OAuth token also has propagation realities across resource servers, as RFC 7009 notes. This incident might be a document ACL change rather than token revocation, so a token endpoint alone cannot solve it.
First set the actual product contract. Does revocation stop new requests, or must it stop already-running generation within a bounded time? For a sensitive corpus I would carry a tenant and document permission epoch into the stream, subscribe or poll for relevant changes, and cancel generation and outbound delivery when that epoch is stale. The check must cover more than the model worker. A gateway that has already buffered a chunk could release it after cancellation. A stream fan-out service might continue replaying saved tokens to a reconnecting client. Measure the maximum interval from policy commit to the last byte delivered under each route.
A per-token synchronous policy lookup would create a new availability and latency bottleneck. A bounded freshness lease or revocation push with an explicit fail-closed behavior on high-risk streams is a more workable design, provided its delay is actually tested. Do not claim strong instant revocation unless all serving and buffer paths obey it. And once a token reached the browser, it cannot be withdrawn. The guarantee can only cover future delivery, with a measured cutoff.
I would test revocation before retrieval, after retrieval but before the first token, during generation, and during browser reconnect. Log the decision version, retrieved document version, revocation commit time, cancel signal time and last emitted byte, without logging private content. That gives the security team a real cutoff bound rather than a promise inferred from the presence of a cancel button.
Continue reading
Related questions
Read beyond the question
Explore more security, governance and platform
Follow another question in this area, or search the complete Question Library.
Browse this area →Browse Question Library →