mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
fix: prevent concurrent token refreshes (#26530)
This can cause bad refresh token errors, since it can only be used once. Looks like there was an attempt to fix this by checking the database after a failed refresh, but of course this depends on the first request having updated the database in time, so both that and this fix are required to fully solve.
This commit is contained in:
@@ -33,6 +33,7 @@ import (
|
||||
"github.com/stretchr/testify/assert"
|
||||
"github.com/stretchr/testify/require"
|
||||
"golang.org/x/oauth2"
|
||||
"golang.org/x/sync/singleflight"
|
||||
"golang.org/x/xerrors"
|
||||
|
||||
"cdr.dev/slog/v3"
|
||||
@@ -1641,6 +1642,7 @@ func (f *FakeIDP) ExternalAuthConfig(t testing.TB, id string, custom *ExternalAu
|
||||
Scopes: []string{},
|
||||
CodeURL: f.locked.Provider().DeviceCodeURL,
|
||||
},
|
||||
RefreshGroup: new(singleflight.Group),
|
||||
}
|
||||
|
||||
if !custom.UseDeviceAuth {
|
||||
|
||||
Reference in New Issue
Block a user