Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[24.2] backport of defensive refresh tokens #19471

Merged
merged 2 commits into from
Jan 28, 2025

Conversation

martenson
Copy link
Member

backport of #19411

openning PR for transparency and maybe some extra eyes

- this will prevent galaxy spamming the auth provider endpoint with doomed refresh attempts for each of these users' request
-afaik the consensus is that we do not log out user in this case atm, details in galaxyproject#15300
we are not guaranteed to have it
@github-actions github-actions bot added the area/auth Authentication and authorization label Jan 28, 2025
@mvdbeek mvdbeek merged commit c8c9c2c into galaxyproject:release_24.2 Jan 28, 2025
50 of 53 checks passed
@martenson martenson deleted the backport-19411 branch January 28, 2025 18:31
@jdavcs jdavcs added this to the 24.2 milestone Feb 3, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
area/auth Authentication and authorization kind/bug merge
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants