feat: keep original token refresh error in external auth (#19339)

External auth refresh errors lose the original error thrown on the first
refresh. This PR saves that error to the database to be raised on
subsequent refresh attempts
This commit is contained in:
Steven Masley
2025-08-14 09:50:31 -05:00
committed by GitHub
parent 5b5fbbed33
commit 4926410146
8 changed files with 110 additions and 28 deletions
+2
View File
@@ -3065,6 +3065,8 @@ type ExternalAuthLink struct {
// The ID of the key used to encrypt the OAuth refresh token. If this is NULL, the refresh token is not encrypted
OAuthRefreshTokenKeyID sql.NullString `db:"oauth_refresh_token_key_id" json:"oauth_refresh_token_key_id"`
OAuthExtra pqtype.NullRawMessage `db:"oauth_extra" json:"oauth_extra"`
// This error means the refresh token is invalid. Cached so we can avoid calling the external provider again for the same error.
OauthRefreshFailureReason string `db:"oauth_refresh_failure_reason" json:"oauth_refresh_failure_reason"`
}
type File struct {