Browse Source

Backport the changes made in ProcessSigninResponse() to OpenIddict 1.x

pull/570/head
Kévin Chalet 9 years ago
parent
commit
5c0f49b70c
  1. 6
      src/OpenIddict/OpenIddictProvider.Helpers.cs
  2. 25
      src/OpenIddict/OpenIddictProvider.cs

6
src/OpenIddict/OpenIddictProvider.Helpers.cs

@ -456,6 +456,8 @@ namespace OpenIddict
return true;
}
var result = true;
foreach (var token in await tokens.FindByAuthorizationIdAsync(identifier))
{
// Don't change the status of the token used in the token request.
@ -464,10 +466,10 @@ namespace OpenIddict
continue;
}
await TryRevokeTokenAsync(token, context);
result &= await TryRevokeTokenAsync(token, context);
}
return true;
return result;
}
private async Task<bool> TryRedeemTokenAsync([NotNull] TToken token, [NotNull] HttpContext context)

25
src/OpenIddict/OpenIddictProvider.cs

@ -121,11 +121,12 @@ namespace OpenIddict
}
}
// When rolling tokens are enabled, revoke all the previously issued tokens associated
// with the authorization if the request is a grant_type=refresh_token request.
if (options.UseRollingTokens && context.Request.IsRefreshTokenGrantType())
if (context.Request.IsRefreshTokenGrantType())
{
if (!await TryRevokeTokensAsync(context.Ticket, context.HttpContext))
// When rolling tokens are enabled, revoke all the previously issued tokens associated
// with the authorization if the request is a grant_type=refresh_token request.
// If the operation fails, return an error indicating the token is not valid.
if (options.UseRollingTokens && !await TryRevokeTokensAsync(context.Ticket, context.HttpContext))
{
context.Reject(
error: OpenIdConnectConstants.Errors.InvalidGrant,
@ -133,14 +134,13 @@ namespace OpenIddict
return;
}
}
// When rolling tokens are disabled, extend the expiration date
// of the existing token instead of returning a new refresh token
// with a new expiration date if sliding expiration was not disabled.
else if (options.UseSlidingExpiration && context.Request.IsRefreshTokenGrantType())
{
if (!await TryExtendTokenAsync(token, context.Ticket, context.HttpContext, options))
// When rolling tokens are disabled, extend the expiration date
// of the existing token instead of returning a new refresh token
// with a new expiration date if sliding expiration was not disabled.
// If the operation fails, return an error indicating the token is not valid.
if (!options.UseRollingTokens && options.UseSlidingExpiration &&
!await TryExtendTokenAsync(token, context.Ticket, context.HttpContext, options))
{
context.Reject(
error: OpenIdConnectConstants.Errors.InvalidGrant,
@ -148,9 +148,6 @@ namespace OpenIddict
return;
}
// Prevent the OpenID Connect server from returning a new refresh token.
context.IncludeRefreshToken = false;
}
}

Loading…
Cancel
Save