# Extended revocation
* refactors revocation of oauth2 tokens by adding revocation of access_tokens which will result in automatic removal on sso portal side * drops unused return statement on same method * adds assertions for correct revocation responses
This commit is contained in:
+16
-7
@@ -155,25 +155,34 @@ class OAuthToken(UuidModel):
|
|||||||
|
|
||||||
return user
|
return user
|
||||||
|
|
||||||
def revoke(self) -> int:
|
def revoke(self) -> None:
|
||||||
""" Revokes the OAuth2 token of the user
|
""" Revokes the OAuth2 token of the user
|
||||||
|
|
||||||
(/o/revoke_token/ indeed removes the corresponding access token on provider side and invalidates the
|
(/o/revoke_token/ indeed removes the corresponding access token on provider side and invalidates the
|
||||||
submitted refresh token in one step)
|
submitted refresh token in one step)
|
||||||
|
|
||||||
Returns:
|
Returns:
|
||||||
revocation_status_code (int): HTTP status code for revocation of refresh_token
|
|
||||||
"""
|
"""
|
||||||
revoke_url = f"{SSO_SERVER_BASE}o/revoke_token/"
|
revoke_url = f"{SSO_SERVER_BASE}o/revoke_token/"
|
||||||
token = self.refresh_token
|
token_types = [
|
||||||
revocation_status_code = requests.post(
|
(self.refresh_token, "refresh_token"),
|
||||||
|
(self.access_token, "access_token"),
|
||||||
|
]
|
||||||
|
status_codes = []
|
||||||
|
for entry in token_types:
|
||||||
|
status_codes.append(
|
||||||
|
requests.post(
|
||||||
revoke_url,
|
revoke_url,
|
||||||
data={
|
data={
|
||||||
'token': token,
|
'token': entry[0],
|
||||||
'token_type_hint': "refresh_token",
|
'token_type_hint': entry[1],
|
||||||
},
|
},
|
||||||
auth=(OAUTH_CLIENT_ID, OAUTH_CLIENT_SECRET),
|
auth=(OAUTH_CLIENT_ID, OAUTH_CLIENT_SECRET),
|
||||||
).status_code
|
).status_code
|
||||||
|
)
|
||||||
|
|
||||||
|
assert len(status_codes) == 2
|
||||||
|
assert status_codes[0] == 200 and status_codes[1] == 200
|
||||||
|
|
||||||
return revocation_status_code
|
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user