box / box/box-python-sdk

Improve Oauth2 API for handling tokens persistence with SQL

未关闭
#207 2 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看
enhancement
主要语言
Python
星标
459
派生
223
平均合并
8 小时 57 分钟
30 天内合并 PR
13

描述

I'm trying to accommodate storing my tokens in an SQL database, and trying to extend the `OAuth2` class to enable storing and retrieving the tokens from the database. The `_refresh_lock` is something that is naturally also managed by the same database. (You have a conceptually similar implementation for redis with `RedisManagedOAuth2`)

What you would typically do with SQL in order to lock a specific row to update it (exactly what we want to do here) is use the `SELECT ... FOR UPDATE` command, which locks and retrieves the data at the same time

The existing code where the lock is used (https://github.com/box/box-python-sdk/blob/6597e930929f3ee49d4930a53304277167c0a4db/boxsdk/auth/oauth2.py#L201-L202 and https://github.com/box/box-python-sdk/blob/6597e930929f3ee49d4930a53304277167c0a4db/boxsdk/auth/oauth2.py#L305-L306) looks like this :

```python
def refresh():
with self.refresh_lock:
tokens = self.get_tokens()
# ... proceed with logic to update them
```

What I'm looking for is this

```python
def refresh():
with self.select_for_update(...) as tokens:
# ... proceed with logic
```

Well, I can't really extend the class to achieve that unless I rewrite the whole methods `refresh` and `revoke`. I think a better API to express the need to "lock tokens and retrieve them" is with its own context manager function, that can have a default implementation that can be overridden. This contextmanager can be trivially rewritten to use select for update

```python
def refresh():
with self.lock_tokens(...) as tokens:
# ... proceed with logic

@contextmanager
def lock_tokens():
with self.refresh_lock:
yield self.get_tokens()
```

贡献指南

打开贡献指南

调研方向

Start in boxsdk/auth/oauth2.py at the existing refresh_lock uses in refresh and revoke, then compare the RedisManagedOAuth2 implementation. Determine how a lock_tokens context manager could expose both token retrieval and locking while remaining overrideable for SQL SELECT ... FOR UPDATE. Done means SQL-backed token persistence can use the API without rewriting refresh or revoke.

由索引模型根据 Issue 内容生成。

评估

技术栈
python
领域
authentication
Issue 类型
功能
难度
5/5
预计耗时
一周以上
活跃度
停滞
描述清晰度
基本清楚
新手友好度
25/100

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。