box / box/box-python-sdk

Add optional CooperativelyManagedOAuth2 functionality to always check for new tokens

未关闭
#180 0 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看
enhancement
主要语言
Python
星标
459
派生
223
平均合并
8 小时 57 分钟
30 天内合并 PR
13

描述

`CooperativelyManagedOAuth2Mixin` overrides `_get_tokens()`. When `refresh()` or `revoke()` are called, this protected method is called to get the latest tokens. However, the `access_token` property (used by `BoxSession` for all API requests) still uses the cached `_access_token` attribute.

During normal usage, this means that, after another instance has done a refresh, the `BoxSession` will usually make one API call with expired tokens before grabbing the updated tokens.

This makes sense as a default behavior. If the cooperative auth is happening over a network, then the cost of one extra API call per hour is much less than checking for new tokens for every single API call.

But if the cooperation is happening within a process and the mechanism is low-cost, it may be more economical to override the `access_token` property to always call `_get_and_update_current_tokens()` before returning the `_access_token` attribute.

This can be done with a `CooperativelyManagedOAuth2Mixin` subclass, or an `__init__` parameter to toggle the behavior.

There's also the question of whether this is useful functionality to add to the SDK.

贡献指南

打开贡献指南

调研方向

Start with CooperativelyManagedOAuth2Mixin, especially _get_tokens(), _get_and_update_current_tokens(), and the access_token property used by BoxSession. Trace how refresh(), revoke(), and API requests obtain tokens, then compare the subclass and initialization-parameter options. Done means the chosen optional behavior is specified, implemented, and covered for both cached and freshly retrieved tokens.

由索引模型根据 Issue 内容生成。

评估

技术栈
python
领域
authentication
Issue 类型
功能
难度
5/5
预计耗时
一周以上
活跃度
停滞
描述清晰度
基本清楚
新手友好度
25/100

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。