# Extended revocation
* refactors revocation of oauth2 tokens by adding revocation of access_tokens which will result in automatic removal on sso portal side * drops unused return statement on same method * adds assertions for correct revocation responses
This commit is contained in:
+21
-12
@@ -155,25 +155,34 @@ class OAuthToken(UuidModel):
|
||||
|
||||
return user
|
||||
|
||||
def revoke(self) -> int:
|
||||
def revoke(self) -> None:
|
||||
""" Revokes the OAuth2 token of the user
|
||||
|
||||
(/o/revoke_token/ indeed removes the corresponding access token on provider side and invalidates the
|
||||
submitted refresh token in one step)
|
||||
|
||||
Returns:
|
||||
revocation_status_code (int): HTTP status code for revocation of refresh_token
|
||||
|
||||
"""
|
||||
revoke_url = f"{SSO_SERVER_BASE}o/revoke_token/"
|
||||
token = self.refresh_token
|
||||
revocation_status_code = requests.post(
|
||||
revoke_url,
|
||||
data={
|
||||
'token': token,
|
||||
'token_type_hint': "refresh_token",
|
||||
},
|
||||
auth=(OAUTH_CLIENT_ID, OAUTH_CLIENT_SECRET),
|
||||
).status_code
|
||||
token_types = [
|
||||
(self.refresh_token, "refresh_token"),
|
||||
(self.access_token, "access_token"),
|
||||
]
|
||||
status_codes = []
|
||||
for entry in token_types:
|
||||
status_codes.append(
|
||||
requests.post(
|
||||
revoke_url,
|
||||
data={
|
||||
'token': entry[0],
|
||||
'token_type_hint': entry[1],
|
||||
},
|
||||
auth=(OAUTH_CLIENT_ID, OAUTH_CLIENT_SECRET),
|
||||
).status_code
|
||||
)
|
||||
|
||||
assert len(status_codes) == 2
|
||||
assert status_codes[0] == 200 and status_codes[1] == 200
|
||||
|
||||
return revocation_status_code
|
||||
|
||||
|
||||
Reference in New Issue
Block a user