Unverified Commit d4b433b1 authored by Björn Grüning's avatar Björn Grüning Committed by GitHub
Browse files

Merge pull request #19514 from mvdbeek/stop_refresh_without_refresh_token

[24.2] Skip token refresh without refresh token in psa
parents 382aac58 083ed716
Loading
Loading
Loading
Loading
+5 −1
Original line number Diff line number Diff line
@@ -177,7 +177,11 @@ class PSAAuthnz(IdentityProvider):
        user_authnz_token.set_extra_data(extra_data)

    def refresh(self, trans, user_authnz_token):
        if not user_authnz_token or not user_authnz_token.extra_data:
        if (
            not user_authnz_token
            or not user_authnz_token.extra_data
            or "refresh_token" not in user_authnz_token.extra_data
        ):
            return False
        # refresh tokens if they reached their half lifetime
        if "expires" in user_authnz_token.extra_data: