fix: validation of refreshed sessions using the access_token in the OIDC provider (#1933)

Signed-off-by: Jan Larwig <jan@larwig.com>
This commit is contained in:
Michi Gysel
2025-11-08 13:49:48 +01:00
committed by GitHub
parent f3f30fa976
commit 22053dcade
3 changed files with 25 additions and 8 deletions
+3 -2
View File
@@ -29,8 +29,9 @@ type SessionState struct {
PreferredUsername string `msgpack:"pu,omitempty"`
// Internal helpers, not serialized
Clock func() time.Time `msgpack:"-"` // override for time.Now, for testing
Lock Lock `msgpack:"-"`
Clock func() time.Time `msgpack:"-"` // override for time.Now, for testing
Lock Lock `msgpack:"-"`
Refreshed bool `msgpack:"-"` // indicates whether the session was refreshed
}
func (s *SessionState) now() time.Time {