Add optional CooperativelyManagedOAuth2 functionality to always check for new tokens
- 主要语言
- Python
- 星标
- 459
- 派生
- 223
- 平均合并
- 8 小时 57 分钟
- 30 天内合并 PR
- 13
描述
`CooperativelyManagedOAuth2Mixin` overrides `_get_tokens()`. When `refresh()` or `revoke()` are called, this protected method is called to get the latest tokens. However, the `access_token` property (used by `BoxSession` for all API requests) still uses the cached `_access_token` attribute.
During normal usage, this means that, after another instance has done a refresh, the `BoxSession` will usually make one API call with expired tokens before grabbing the updated tokens.
This makes sense as a default behavior. If the cooperative auth is happening over a network, then the cost of one extra API call per hour is much less than checking for new tokens for every single API call.
But if the cooperation is happening within a process and the mechanism is low-cost, it may be more economical to override the `access_token` property to always call `_get_and_update_current_tokens()` before returning the `_access_token` attribute.
This can be done with a `CooperativelyManagedOAuth2Mixin` subclass, or an `__init__` parameter to toggle the behavior.
There's also the question of whether this is useful functionality to add to the SDK.
贡献指南
调研方向
Start with CooperativelyManagedOAuth2Mixin, especially _get_tokens(), _get_and_update_current_tokens(), and the access_token property used by BoxSession. Trace how refresh(), revoke(), and API requests obtain tokens, then compare the subclass and initialization-parameter options. Done means the chosen optional behavior is specified, implemented, and covered for both cached and freshly retrieved tokens.
由索引模型根据 Issue 内容生成。
评估
- 技术栈
- python
- 领域
- authentication
- Issue 类型
- 功能
- 难度
- 5/5
- 预计耗时
- 一周以上
- 活跃度
- 停滞
- 描述清晰度
- 基本清楚
- 新手友好度
- 25/100