Skip to content

Conversation

@vmourot
Copy link
Contributor

@vmourot vmourot commented Apr 15, 2025

Description

The 3600 second expiration time of a new oAuth2 token is now configurable with the key 'oauth2-token-expiration-time-seconds'. The value si 3600 by default to make no regression if the conf value is not present.

This commit is for debug purpose on clients that manages oAuth2 tokens.

Fixes

  • No ticket

Type of change

  • Chore (PATCH)
  • Doc (PATCH)
  • Bug fix (PATCH)
  • New feature (MINOR)

Which packages changed?

Please check the name of the package you changed

  • admin
  • app-registry
  • archive
  • auth
  • cas
  • common
  • communication
  • conversation
  • directory
  • feeder
  • infra
  • portal
  • session
  • test
  • tests
  • timeline
  • workspace

Tests

Without define a value in conf for 'oauth2-token-expiration-time-seconds', no changes are expected.
When this value is defined, the 'expiresIn' value in response for POST /auth/oauth2/token has to be equal to the configured value.

Reminder

  • Security flaws

  • Performance impacts (think bulk !)

  • Unit tests were replayed

  • Unit tests were added and/or changed

  • I have updated the reminder for the version including my modifications

  • All done ! 😃

jenkinsEdificePublic and others added 2 commits February 26, 2025 14:06
Read a new conf value named 'oauth2-token-expiration-time-seconds' with a default value of 3600
@vmourot vmourot requested a review from nabil-mansouri April 15, 2025 09:43
@vmourot vmourot self-assigned this Apr 15, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants