Skip to content

docs: LongPort token durability plan + read-only expiry inspect - #585

Merged
Pigbibi merged 1 commit into
mainfrom
docs/longport-token-refresh-plan-20261009
Oct 9, 2026
Merged

Pigbibi merged 1 commit into
mainfrom
docs/longport-token-refresh-plan-20261009

Conversation

@Pigbibi

@Pigbibi Pigbibi commented Oct 9, 2026

Copy link
Copy Markdown
Collaborator

Summary

  • Document how paper/HK/SG store LongPort credentials (SM names only), why in-runtime refresh_token_if_needed historically failed to prevent expiry, and recommend path A (pre-expiry Legacy refresh) before OAuth2.
  • Add a read-only workflow_dispatch JWT expiry inspector (names + days remaining only; no /v1/token/refresh, no SM writes).
  • Exact next PR scope (QPK expired_at + fail-closed, then scheduled refresh paper→sg→HK last) lives in the runbook.

Test plan

  • venv: pytest -q tests/test_inspect_longport_token_expiry.py (6 passed)
  • After merge: manually dispatch Inspect LongPort Token Expiry for paper then sg (HK last optional); confirm summary shows days only, no secret material
  • Does not rotate secrets, enable strategy, or change ingress

Refs: Getting Started, Refresh API, 401003

Add runbook for paper/HK/SG Legacy token storage, why in-cycle refresh
missed expiry (probe read-only + paused strategy), and path A before OAuth.
Ship a workflow_dispatch JWT expiry inspector that never refreshes or
writes Secret Manager versions.
@Pigbibi
Pigbibi merged commit b723665 into main Oct 9, 2026
1 check passed
@Pigbibi
Pigbibi deleted the docs/longport-token-refresh-plan-20261009 branch October 9, 2026 06:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant