馃悰 Guard expires_latency when a token has no known expiry - #765
Merged
Merged
Conversation
AccessToken#initialize subtracted expires_latency from expires_at whenever expires_latency was set, without checking that expires_at was set. So a token without expires_in/expires_at (RFC 6749 section 5.1 makes expires_in RECOMMENDED, not REQUIRED), or with expires_in: 0, raised NoMethodError (undefined method '-' for nil). This broke client.get_token(params, expires_latency: N) against providers that issue non-expiring tokens and omit expires_in. Only apply the latency when an expiry is known. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Signed-off-by: iamibi <8592115+iamibi@users.noreply.github.com>
Contributor
Author
|
The red checks aren't from this change. They fail the same way on
Two fail only because this PR comes from a fork: the QLTY upload in Test Coverage (no OIDC token for fork PRs) and Auto Assign (read-only token). In that coverage job the suite itself passed, with 596 examples, 0 failures and 100% line coverage (job). Happy to send separate PRs for any of these if that helps. |
Member
|
I am working on fixes for all the failures in main already. Thanks for fixing this issue! I will be releasing a new patch version of oauth2 soon, so this should get into that release. |
pboling
approved these changes
Sep 29, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #764
AccessToken#initializesubtractedexpires_latencyfromexpires_ateven when no expiry was known. A token whose response had neitherexpires_innorexpires_at, or hadexpires_in: 0, therefore raisedNoMethodError(undefined method '-' for nil). For example,client.get_token(params, expires_latency: 30)failed against any provider that issues non-expiring tokens and so omitsexpires_in, which RFC 6749 搂5.1 allows.Change
lib/oauth2/access_token.rb:@expires_at -= @expires_latency if @expires_at && @expires_latency, the form suggested in the #394 review. Such a token doesn't expire and keepsexpires_latency. Tokens with a known expiry behave as before.CHANGELOG.md: an entry under[Unreleased]/Fixed.Tests
New examples in the
expires_latencyblock ofspec/oauth2/access_token_spec.rb:expires_innorexpires_atis provided: does not raise, does not expire, retainsexpires_latency;expires_inis zero: does not raise, does not expire;expires_in: builds a non-expiring token viaClient#get_token.Against the unpatched code, all 6 new examples fail with the
NoMethodError. With the fix, the fullbundle exec kettle-testsuite passes: 596 examples, 0 failures, 100% line coverage (558/558). The existing examples are unchanged.Checklist
CHANGELOG.mdentry under[Unreleased]Signed-off-byand a signed commitbundle exec rubocop-gradual: no new offensesbin/rake reek: no new warnings