diff --git a/lib/galaxy/authnz/managers.py b/lib/galaxy/authnz/managers.py index c16194b5708..2578db9ebf3 100644 --- a/lib/galaxy/authnz/managers.py +++ b/lib/galaxy/authnz/managers.py @@ -342,8 +342,11 @@ class AuthnzManager: return None for auth in user.social_auth or []: result = self.refresh_expiring_oidc_tokens_for_provider(trans, auth) + config = self.oidc_backends_config.get(auth.provider, None) + if config is None: + continue # Redirect to OIDC login if refresh fails and require_refresh is enabled - if trans.app.config.oidc_require_refresh and result["reauthentication_required"]: + if config.get("require_session_refresh") and result["reauthentication_required"]: return auth.provider return None diff --git a/lib/galaxy/webapps/base/webapp.py b/lib/galaxy/webapps/base/webapp.py index 93ab1e6d5e2..76980af1c34 100644 --- a/lib/galaxy/webapps/base/webapp.py +++ b/lib/galaxy/webapps/base/webapp.py @@ -358,10 +358,10 @@ class GalaxyWebTransaction(base.DefaultWebTransaction, context.ProvidesHistoryCo self._ensure_valid_session(session_cookie) if hasattr(self.app, "authnz_manager") and self.app.authnz_manager: - # Check for expiring tokens and refresh them. If configured, require a reauthentication - # on failed refresh. + # Check for expiring tokens and refresh them. If configured (at the individual provider + # level), require a reauthentication on failed refresh. reauth_provider = self.app.authnz_manager.refresh_expiring_oidc_tokens(self) - if self.app.config.oidc_require_refresh and reauth_provider: + if reauth_provider: self.handle_user_reauthentication(reauth_provider) return