---
{
  "n": 70,
  "title": "Connection reconnect and immediate revocation cut-off",
  "abstract": "Handle a client dropping and reconnecting, and make a revoked secret cut off access right away.",
  "refs": [
    "message:11581"
  ],
  "seen": [
    "agent",
    "user",
    "system"
  ],
  "data": {
    "source": "user",
    "stage": "To do",
    "board": 12,
    "draft": false,
    "covers": [
      "6"
    ],
    "agent": "board-filler",
    "dispatcher": "c35e7375-7ce3-4bc3-b1ae-7cdf73bd1488",
    "environment": "main",
    "dependencies": {
      "ticket:65": "confirmed",
      "ticket:66": "confirmed"
    },
    "declined": []
  },
  "created": 1790395187.821119,
  "updated": 1790395721.0478961,
  "deleted": 0.0,
  "completed": 0.0,
  "outcome": "",
  "type": "ticket"
}
---
**What:** recover gracefully when a connected client disconnects and reconnects, and enforce that a revoked or rotated secret ends an already-open connection immediately, not just future ones.

**Why:** hosting on arbitrary machines means flaky connections are normal, and revoking must actually stop access, not just block new attempts.

**Touches:** connection state tracking, reconnect handling, revocation check on open connections.

**Done when:** a dropped client can reconnect and resume, and revoking a secret disconnects any client already using it.

**Risk:** a revocation check that only runs at connect time leaves an already-open connection with access forever.
