Conversation
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## master #780 +/- ##
============================================
+ Coverage 76.06% 77.72% +1.66%
- Complexity 325 351 +26
============================================
Files 33 33
Lines 1291 1347 +56
Branches 178 191 +13
============================================
+ Hits 982 1047 +65
+ Misses 227 221 -6
+ Partials 82 79 -3 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Harden the expired OIDC token path so concurrent Jenkins requests do not
trigger refresh storms or redirect AJAX calls into an interactive login, and
restart login safely when an old callback arrives with missing or mismatched
session state.
This supersedes the closed #748 and preserves @scheremisin's authorship on the
rebased refresh-hardening commit. It also incorporates the focused behavior
discussed in #753 and adds callback-state recovery observed while reproducing
the same failure family.
Related reports and proposals: #411, #467, #706, #748, #753.
Changes
the lock, so rotated refresh tokens are not reused concurrently.
omits the optional
grant_types_supportedfield.401 Unauthorizedto AJAX and other non-interactive requests insteadof redirecting them into the OIDC authorization flow.
redirects.
invalid_grantrefresh response so pollingrequests do not retry a known-invalid refresh token.
session state, without calling the token endpoint.
tests.
Why this is needed
Jenkins pages routinely issue several concurrent widget and AJAX requests. If
the access token expires while the Jenkins HTTP session remains valid, all of
those requests can observe the same credentials. Providers that rotate refresh
tokens may accept the first refresh and reject the others with
invalid_grant. If refresh is unavailable, redirecting an AJAX request to theauthorization endpoint can also produce CORS errors, stale crumbs, nested-path
login URLs, and multiple overlapping callbacks.
OIDC discovery defines
grant_types_supportedas optional. Its absence shouldnot override the stronger runtime signal that the provider already issued a
refresh token.
Testing done
The new tests execute:
Submitter checklist