Repository navigation
Token refresh: Do not report transient failures as expired token - #237
Open
paolostivanin wants to merge 1 commit into
Open
paolostivanin wants to merge 1 commit into
paolostivanin wants to merge 1 commit into
Conversation
Any failed silent token refresh (network error, timeout, IdP 5xx, failed OIDC discovery) ended in an empty bearer token, a second 401 and the "token expired, sign in again" prompt. Background uploads were marked as permanently failed. - AccountAuthenticator now tells a refresh token rejected by the IdP (invalid_grant and similar) from a transient failure. Only the former asks for a new login. The latter is reported as a connection problem and the stored tokens are kept. - ConnectionValidator no longer counts a failed refresh as a success and does not retry with stale credentials. - mTLS: the validation probe and the OIDC discovery and refresh requests now present the account's client certificate. - Serialize refreshes with a lock and store the rotated refresh token before the access token. - Stop logging tokens.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
Users are often sent back to the login screen with "The access token has expired or become invalid". Any failed silent token refresh (network error, timeout, IdP 5xx, failed OIDC discovery) was reported that way. The authenticator returned nothing, the request was retried with an empty
Bearerheader, got a second 401 and surfaced as an expired session. Background uploads were marked as permanently failed. With mTLS there were two more problems on the same path.Changes
AccountAuthenticatortells a refresh token rejected by the IdP (invalid_grant,invalid_client,unauthorized_client,access_denied) from a transient failure. Only a rejection asks for a new login. A transient failure throwsNetworkErrorException, which reaches the callers as a connection problem (TokenRefreshFailedException, aSocketException) so it is retried and the stored tokens are kept.TokenRequestRemoteOperationmaps a rejected refresh grant toOAUTH2_ERROR. The login (authorization code) grant keeps its mapping.ConnectionValidatorno longer counts a failed refresh as a success and does not retry with stale credentials.clearPasswordfor OAuth accounts, which wiped a token refreshed by a concurrent request.FileDisplayActivitychecksAccountUtils.isOAuth2Accountinstead of loading credentials, which could trigger another refresh.Testing
ConnectionValidatorTest,AccountAuthenticatorTest, and refresh error mapping inOAuthRemoteOperationTest. The two behavioural validator tests fail on the old code.