mirror of
https://github.com/GNS3/gns3-server.git
synced 2026-08-27 20:40:13 +03:00
_resolve_token generated a temp JWT with a hardcoded ver=0 after validating the API key. Users who had logged out at least once (token_version >= 1) would hit "Token has been revoked" 401 on every MCP tool call, because the REST auth chain rejects ver=0 when the user's token_version no longer matches. Fix: pass the user's actual token_version to create_access_token so the temp JWT carries the correct ver claim.