felangel / felangel/fresh

should be able to inject error into response if token refreshing fails

Ouverte
#48 4 commentaires 0 réactions 1 personne assignée Réclamée par @felangel Voir sur GitHub
enhancement
Langage dominant
Dart
Étoiles
428
Forks
60
Métriques de merge des PR
Aucune PR mergée en 30 j

Description

Hi there! This is by far the most intuitive package for refreshing tokens in graphql. Here is one enhancement that I would like to see:

in a case like this:

```dart
refreshToken: (token, client) async {
await tokenManager.refresh();
}
```
if there is an error in refreshing the token, it is not possible to get it to the client; any thrown error here is "swallowed". If the api looked something like this:

```dart
refreshToken: (token, client, resp) async {
await tokenManager.refresh();
}
```

then you could do something like:

```dart
refreshToken: (token, client, resp) async {
try {
await tokenManager.refresh();
} catch {
resp.errors.add(GraphQLError(message: 'Error refreshing access tokens`));
}
}
```

and then it would be easy to log the user out or similar in a situation like this. Right now, I'm just assuming if `response.hasErrors && response.errors == null` then this is an error in the refresh token, which is obviously not a robust assumption (as it's possible that the response would have errors but no errors have been added for other reasons.)

I don't think it's an unfair assumption to believe that for some reason, a token refresh could fail: for instance, if a refresh token is compromised manually resetting it on the server would cause the refresh to fail; in a situation like this, I probably want to log the user out.

Thanks for the package! It helps a lot in my development.

Guide de contribution

Aucun guide de contribution indexé pour ce dépôt

Évaluation

Cette issue n'a pas encore été évaluée.

Recevez les nouvelles issues par e-mail

Un résumé court des issues GitHub adaptées aux débutants.