fix: prevent concurrent token refreshes (#26530)

This can cause bad refresh token errors, since it can only be used once.

Looks like there was an attempt to fix this by checking the database
after a failed refresh, but of course this depends on the first request
having updated the database in time, so both that and this fix are 
required to fully solve.
This commit is contained in:
Asher
2026-07-15 12:16:25 -08:00
committed by GitHub
parent c14b4a010a
commit 4d4cbd07e6
12 changed files with 460 additions and 38 deletions
+2
View File
@@ -33,6 +33,7 @@ import (
"github.com/stretchr/testify/assert"
"github.com/stretchr/testify/require"
"golang.org/x/oauth2"
"golang.org/x/sync/singleflight"
"golang.org/x/xerrors"
"cdr.dev/slog/v3"
@@ -1641,6 +1642,7 @@ func (f *FakeIDP) ExternalAuthConfig(t testing.TB, id string, custom *ExternalAu
Scopes: []string{},
CodeURL: f.locked.Provider().DeviceCodeURL,
},
RefreshGroup: new(singleflight.Group),
}
if !custom.UseDeviceAuth {