spring-attic/spring-cloud-security

OAuth2 intercepter for feign does not re-issue invalid token

開放

#220 建立於 2019年9月2日

 (3 則留言) (8 個反應) (0 位負責人)Java (250 個分叉)batch import
enhancementhelp wanted

倉庫指標

星標
 (525 顆星)
PR 合併指標
 (30 天內沒有已合併 PR)

描述

Hi,

If we check OAuth2RestTemplate it has an option retryBadAccessTokens which will try one more time to obtain new access token if previous token is invalid. This is useful if, for some reasons, you decide to revoke access token.

In OAuth2FeignRequestInterceptor access token is preserved in client context until it expires. There is no way to make feign to reissue new token until it expire.

The difficulty here that in feign interceptor is not responsible for retry. So what will be correct way to handle this issue? One of the option is to implement a feign retryer which will clean up client context.

If it is correct, do you want me to try to contribute this change?

貢獻者指南