You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
feat(client): optional 401 auto-refresh hook so user-session apps can drop proactive is_expired() checks #89
Deferred from #87 (item 3, "smaller"): JsonClient-level auto-refresh on 401 would let user-session apps stop depending on proactive is_expired() checks. campus-classroom leans on with_user_session()'s proactive refresh; a token that expires mid-request (expiry-skew window) still surfaces the 401 to the app.
Problem
CampusRequest (json_client/init.py) has no retry path: a 401 from any verb propagates to the caller. Apps must pre-empt expiry themselves (_get_token_from_session(refresh_if_expired=True)), which cannot close the race where the token dies between the proactive check and the request.
Suggested shape
An opt-in hook on CampusRequest (e.g. set_unauthorized_hook(fn) or a refresh= constructor arg): on a 401 response, invoke the hook once, then retry the request with the refreshed Authorization header. No retry on a second 401.
Deferred from #87 (item 3, "smaller"): JsonClient-level auto-refresh on 401 would let user-session apps stop depending on proactive
is_expired()checks. campus-classroom leans onwith_user_session()'s proactive refresh; a token that expires mid-request (expiry-skew window) still surfaces the 401 to the app.Problem
CampusRequest(json_client/init.py) has no retry path: a 401 from any verb propagates to the caller. Apps must pre-empt expiry themselves (_get_token_from_session(refresh_if_expired=True)), which cannot close the race where the token dies between the proactive check and the request.Suggested shape
CampusRequest(e.g.set_unauthorized_hook(fn)or arefresh=constructor arg): on a 401 response, invoke the hook once, then retry the request with the refreshed Authorization header. No retry on a second 401.auth.refresh(stored)from feat(auth): refresh grant + device-flow parity for public clients #88.JsonClientis an ABC wrapping requests and flask.test.Client; the hook belongs on the concreteCampusRequest, with the ABC documenting it.Reference: #87 (closed by #88, which delivered the refresh grant + device-flow parity items).