# Extended revocation

* refactors revocation of oauth2 tokens by adding revocation of access_tokens which will result in automatic removal on sso portal side
* drops unused return statement on same method
* adds assertions for correct revocation responses
This commit is contained in:
2026-10-06 11:44:56 +02:00
parent 87aea5e19b
commit cc0f4007f3
+21 -12
View File
@@ -155,25 +155,34 @@ class OAuthToken(UuidModel):
return user
def revoke(self) -> int:
def revoke(self) -> None:
""" Revokes the OAuth2 token of the user
(/o/revoke_token/ indeed removes the corresponding access token on provider side and invalidates the
submitted refresh token in one step)
Returns:
revocation_status_code (int): HTTP status code for revocation of refresh_token
"""
revoke_url = f"{SSO_SERVER_BASE}o/revoke_token/"
token = self.refresh_token
revocation_status_code = requests.post(
revoke_url,
data={
'token': token,
'token_type_hint': "refresh_token",
},
auth=(OAUTH_CLIENT_ID, OAUTH_CLIENT_SECRET),
).status_code
token_types = [
(self.refresh_token, "refresh_token"),
(self.access_token, "access_token"),
]
status_codes = []
for entry in token_types:
status_codes.append(
requests.post(
revoke_url,
data={
'token': entry[0],
'token_type_hint': entry[1],
},
auth=(OAUTH_CLIENT_ID, OAUTH_CLIENT_SECRET),
).status_code
)
assert len(status_codes) == 2
assert status_codes[0] == 200 and status_codes[1] == 200
return revocation_status_code