refactor: update logic for refreshing tokens

This commit is contained in:
marius-mather
2026-04-29 13:31:00 +10:00
parent 58632d14de
commit acdd9c1263
2 changed files with 7 additions and 4 deletions
+4 -1
View File
@@ -342,8 +342,11 @@ class AuthnzManager:
return None
for auth in user.social_auth or []:
result = self.refresh_expiring_oidc_tokens_for_provider(trans, auth)
config = self.oidc_backends_config.get(auth.provider, None)
if config is None:
continue
# Redirect to OIDC login if refresh fails and require_refresh is enabled
if trans.app.config.oidc_require_refresh and result["reauthentication_required"]:
if config.get("require_session_refresh") and result["reauthentication_required"]:
return auth.provider
return None
+3 -3
View File
@@ -358,10 +358,10 @@ class GalaxyWebTransaction(base.DefaultWebTransaction, context.ProvidesHistoryCo
self._ensure_valid_session(session_cookie)
if hasattr(self.app, "authnz_manager") and self.app.authnz_manager:
# Check for expiring tokens and refresh them. If configured, require a reauthentication
# on failed refresh.
# Check for expiring tokens and refresh them. If configured (at the individual provider
# level), require a reauthentication on failed refresh.
reauth_provider = self.app.authnz_manager.refresh_expiring_oidc_tokens(self)
if self.app.config.oidc_require_refresh and reauth_provider:
if reauth_provider:
self.handle_user_reauthentication(reauth_provider)
return