mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
feat: add best effort attempt to revoke oauth access token in external auth provider (#19775)
Solves #15575 Adds OAuth access token revocation when unlinking external auth provider. Due to revocation not being consistently implemented by providers this is only best effort attempt. Unsuccessful revocation won't influence link removal.
This commit is contained in:
@@ -2692,6 +2692,8 @@ func parseExternalAuthProvidersFromEnv(prefix string, environ []string) ([]coder
|
||||
provider.AuthURL = v.Value
|
||||
case "TOKEN_URL":
|
||||
provider.TokenURL = v.Value
|
||||
case "REVOKE_URL":
|
||||
provider.RevokeURL = v.Value
|
||||
case "VALIDATE_URL":
|
||||
provider.ValidateURL = v.Value
|
||||
case "REGEX":
|
||||
|
||||
@@ -77,6 +77,7 @@ func TestReadExternalAuthProvidersFromEnv(t *testing.T) {
|
||||
"CODER_EXTERNAL_AUTH_1_CLIENT_SECRET=hunter12",
|
||||
"CODER_EXTERNAL_AUTH_1_TOKEN_URL=google.com",
|
||||
"CODER_EXTERNAL_AUTH_1_VALIDATE_URL=bing.com",
|
||||
"CODER_EXTERNAL_AUTH_1_REVOKE_URL=revoke.url",
|
||||
"CODER_EXTERNAL_AUTH_1_SCOPES=repo:read repo:write",
|
||||
"CODER_EXTERNAL_AUTH_1_NO_REFRESH=true",
|
||||
"CODER_EXTERNAL_AUTH_1_DISPLAY_NAME=Google",
|
||||
@@ -88,6 +89,7 @@ func TestReadExternalAuthProvidersFromEnv(t *testing.T) {
|
||||
// Validate the first provider.
|
||||
assert.Equal(t, "1", providers[0].ID)
|
||||
assert.Equal(t, "gitlab", providers[0].Type)
|
||||
assert.Equal(t, "", providers[0].RevokeURL)
|
||||
|
||||
// Validate the second provider.
|
||||
assert.Equal(t, "2", providers[1].ID)
|
||||
@@ -95,6 +97,7 @@ func TestReadExternalAuthProvidersFromEnv(t *testing.T) {
|
||||
assert.Equal(t, "hunter12", providers[1].ClientSecret)
|
||||
assert.Equal(t, "google.com", providers[1].TokenURL)
|
||||
assert.Equal(t, "bing.com", providers[1].ValidateURL)
|
||||
assert.Equal(t, "revoke.url", providers[1].RevokeURL)
|
||||
assert.Equal(t, []string{"repo:read", "repo:write"}, providers[1].Scopes)
|
||||
assert.Equal(t, true, providers[1].NoRefresh)
|
||||
assert.Equal(t, "Google", providers[1].DisplayName)
|
||||
|
||||
Reference in New Issue
Block a user