mirror of
https://github.com/galaxyproject/galaxy.git
synced 2026-09-24 16:30:27 +08:00
refactor: update logic for refreshing tokens
This commit is contained in:
@@ -342,8 +342,11 @@ class AuthnzManager:
|
||||
return None
|
||||
for auth in user.social_auth or []:
|
||||
result = self.refresh_expiring_oidc_tokens_for_provider(trans, auth)
|
||||
config = self.oidc_backends_config.get(auth.provider, None)
|
||||
if config is None:
|
||||
continue
|
||||
# Redirect to OIDC login if refresh fails and require_refresh is enabled
|
||||
if trans.app.config.oidc_require_refresh and result["reauthentication_required"]:
|
||||
if config.get("require_session_refresh") and result["reauthentication_required"]:
|
||||
return auth.provider
|
||||
return None
|
||||
|
||||
|
||||
@@ -358,10 +358,10 @@ class GalaxyWebTransaction(base.DefaultWebTransaction, context.ProvidesHistoryCo
|
||||
self._ensure_valid_session(session_cookie)
|
||||
|
||||
if hasattr(self.app, "authnz_manager") and self.app.authnz_manager:
|
||||
# Check for expiring tokens and refresh them. If configured, require a reauthentication
|
||||
# on failed refresh.
|
||||
# Check for expiring tokens and refresh them. If configured (at the individual provider
|
||||
# level), require a reauthentication on failed refresh.
|
||||
reauth_provider = self.app.authnz_manager.refresh_expiring_oidc_tokens(self)
|
||||
if self.app.config.oidc_require_refresh and reauth_provider:
|
||||
if reauth_provider:
|
||||
self.handle_user_reauthentication(reauth_provider)
|
||||
return
|
||||
|
||||
|
||||
Reference in New Issue
Block a user