Improve Oauth2 API for handling tokens persistence with SQL
- 主要语言
- Python
- 星标
- 459
- 派生
- 223
- 平均合并
- 8 小时 57 分钟
- 30 天内合并 PR
- 13
描述
I'm trying to accommodate storing my tokens in an SQL database, and trying to extend the `OAuth2` class to enable storing and retrieving the tokens from the database. The `_refresh_lock` is something that is naturally also managed by the same database. (You have a conceptually similar implementation for redis with `RedisManagedOAuth2`)
What you would typically do with SQL in order to lock a specific row to update it (exactly what we want to do here) is use the `SELECT ... FOR UPDATE` command, which locks and retrieves the data at the same time
The existing code where the lock is used (https://github.com/box/box-python-sdk/blob/6597e930929f3ee49d4930a53304277167c0a4db/boxsdk/auth/oauth2.py#L201-L202 and https://github.com/box/box-python-sdk/blob/6597e930929f3ee49d4930a53304277167c0a4db/boxsdk/auth/oauth2.py#L305-L306) looks like this :
```python
def refresh():
with self.refresh_lock:
tokens = self.get_tokens()
# ... proceed with logic to update them
```
What I'm looking for is this
```python
def refresh():
with self.select_for_update(...) as tokens:
# ... proceed with logic
```
Well, I can't really extend the class to achieve that unless I rewrite the whole methods `refresh` and `revoke`. I think a better API to express the need to "lock tokens and retrieve them" is with its own context manager function, that can have a default implementation that can be overridden. This contextmanager can be trivially rewritten to use select for update
```python
def refresh():
with self.lock_tokens(...) as tokens:
# ... proceed with logic
@contextmanager
def lock_tokens():
with self.refresh_lock:
yield self.get_tokens()
```
贡献指南
调研方向
Start in boxsdk/auth/oauth2.py at the existing refresh_lock uses in refresh and revoke, then compare the RedisManagedOAuth2 implementation. Determine how a lock_tokens context manager could expose both token retrieval and locking while remaining overrideable for SQL SELECT ... FOR UPDATE. Done means SQL-backed token persistence can use the API without rewriting refresh or revoke.
由索引模型根据 Issue 内容生成。
评估
- 技术栈
- python
- 领域
- authentication
- Issue 类型
- 功能
- 难度
- 5/5
- 预计耗时
- 一周以上
- 活跃度
- 停滞
- 描述清晰度
- 基本清楚
- 新手友好度
- 25/100