googleapis / googleapis/google-api-nodejs-client

Guidance on saving access/refresh tokens leads to redundant writes

Offen
#1,767 2 Kommentare 4 Reaktionen 1 zugewiesene Person Beansprucht von @jasonpolites Auf GitHub ansehen
size: m type: docs
Vorherrschende Sprache
TypeScript
Sterne
12.3k
Forks
2k
Ø Merge
1 T. 9 Std.
Gemergte PRs (30 T.)
24

Beschreibung

OK.. so my title is a bit click-baity, but still...

The guidance in the readme (ref: [Retrieve access token](https://github.com/googleapis/google-api-nodejs-client#retrieve-access-token)), suggests:

```
// This will provide an object with the access_token and refresh_token.
// Save these somewhere safe so they can be used at a later time.
const {tokens} = await oauth2Client.getToken(code)
oauth2Client.setCredentials(tokens);
```

Saving this token to a database (for example), will result in a duplicate write if we _also_ follow the guidance for refresh tokens (ref: [Handling refresh tokens](https://github.com/googleapis/google-api-nodejs-client#handling-refresh-tokens)), which suggests:

```
oauth2Client.on('tokens', (tokens) => {
if (tokens.refresh_token) {
// store the refresh_token in my database!
console.log(tokens.refresh_token);
}
console.log(tokens.access_token);
});
```

It seems that `oauth2Client.on('tokens')` is called when setting credentials on the client, in which case it's called in the first retrieval of the access token, which then also triggers a call to this method via the `setCredentials` invocation.

_If_ `oauth2Client.on('tokens')` is _always_ called when credentials are set, then maybe it makes sense to change the guidance to only/always use that to store tokens

Beitragsleitfaden

Beitragsleitfaden öffnen

Bewertung

Dieses Issue wurde noch nicht bewertet.

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.