Add RefreshOIDCToken middleware - #301
Open
GermanoGuerrini wants to merge 4 commits into
Open
Conversation
Codecov Report
@@ Coverage Diff @@
## master #301 +/- ##
==========================================
+ Coverage 88.1% 88.76% +0.66%
==========================================
Files 7 7
Lines 437 463 +26
==========================================
+ Hits 385 411 +26
Misses 52 52
Continue to review full report at Codecov.
|
|
Any news on that ? |
|
Any updates? |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
I noticed that the library was missing the ability to use any refresh token issued by the provider.
It can be used in place of a silent user re-authentication (which does not work for the provider I was working with).
Information can be found here.
Now, while the implementation in this pull request works, it misses a proper provider response validation as described in the OpenID Specs.
That would require a serious refactoring in order to store extra information from the original response in a safer place than the user session, like the database, which currently isn't involved at all.
Plus, the validation should be factored out from the OIDCAuthenticationBackend to be re-used wherever needed.
Is there any interest in such contribution?