From 83fed5697fbf77da883ea766ba3010afbf4d43a5 Mon Sep 17 00:00:00 2001 From: John Davis Date: Tue, 6 May 2025 22:20:12 -0400 Subject: [PATCH 1/3] Fix 2 typing errors --- lib/galaxy/authnz/tapis.py | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/lib/galaxy/authnz/tapis.py b/lib/galaxy/authnz/tapis.py index 003fffb6837..455a7f08768 100644 --- a/lib/galaxy/authnz/tapis.py +++ b/lib/galaxy/authnz/tapis.py @@ -31,7 +31,7 @@ class TapisOAuth2(BaseOAuth2): USE_BASIC_AUTH = True # Upstream this is initialized to None, but it is expected this will be a list of tuples - EXTRA_DATA = [ # type: ignore[assignment] + EXTRA_DATA = [ ("refresh_token", "refresh_token"), ] @@ -92,6 +92,7 @@ class TapisOAuth2(BaseOAuth2): ) self.process_error(response) result = response.get("result") + assert result token = result.get("access_token") # ignore B026, we keep the same signature as the base class return self.do_auth(token, response=response, *args, **kwargs) # noqa: B026 From 90fcafe67ab9ee47318431b733130c914716e3f6 Mon Sep 17 00:00:00 2001 From: Dannon Baker Date: Thu, 8 May 2025 13:26:34 -0400 Subject: [PATCH 2/3] Simplify access method; tapis will only use post. This diverges auth_complete a bit more from the parent method, but it's fine. --- lib/galaxy/authnz/tapis.py | 9 +++------ 1 file changed, 3 insertions(+), 6 deletions(-) diff --git a/lib/galaxy/authnz/tapis.py b/lib/galaxy/authnz/tapis.py index 455a7f08768..39e68ab60b4 100644 --- a/lib/galaxy/authnz/tapis.py +++ b/lib/galaxy/authnz/tapis.py @@ -76,16 +76,13 @@ class TapisOAuth2(BaseOAuth2): """Completes login process, must return user instance""" self.process_error(self.data) state = self.validate_state() - data, params = None, None - if self.ACCESS_TOKEN_METHOD == "GET": - params = self.auth_complete_params(state) - else: - data = self.auth_complete_params(state) + + data = self.auth_complete_params(state) response = self.request_access_token( self.access_token_url(), data=data, - params=params, + params=None, headers=self.auth_headers(), auth=self.auth_complete_credentials(), method=self.ACCESS_TOKEN_METHOD, From 1917dfc7584b47b7381476039d97ada90f5d3b52 Mon Sep 17 00:00:00 2001 From: Dannon Baker Date: Thu, 8 May 2025 13:34:37 -0400 Subject: [PATCH 3/3] Add error handling for missing result and access token in Tapis authentication response --- lib/galaxy/authnz/tapis.py | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/lib/galaxy/authnz/tapis.py b/lib/galaxy/authnz/tapis.py index 39e68ab60b4..11861cecc3f 100644 --- a/lib/galaxy/authnz/tapis.py +++ b/lib/galaxy/authnz/tapis.py @@ -89,8 +89,11 @@ class TapisOAuth2(BaseOAuth2): ) self.process_error(response) result = response.get("result") - assert result + if not result: + raise ValueError("No result found in Tapis authentication response") token = result.get("access_token") + if not token: + raise ValueError("No access token found in Tapis authentication response") # ignore B026, we keep the same signature as the base class return self.do_auth(token, response=response, *args, **kwargs) # noqa: B026