feat(security): let a consumer supply the access token via setAccessTokenResolver - #324
feat(security): let a consumer supply the access token via setAccessTokenResolver#324gcutrini wants to merge 2 commits into
Conversation
|
Important Draft PR not reviewedDraft PRs are not automatically reviewed by default.
To automatically review draft PRs, update your CodeRabbit configuration: reviews:
auto_review:
drafts: trueThanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
…okenResolver Add setAccessTokenResolver: when a resolver is registered, getAccessToken delegates to it; otherwise the built-in flow is unchanged. Passing a non-function resets to the built-in. The resolver is module-level state, so externalize security/methods in the webpack build so every uicore lib entry shares one instance and sees the registered resolver.
Delegates to a registered resolver, a later resolver replaces the previous one, and a non-function argument clears it.
670afb2 to
63e4c51
Compare
|
@gcutrini i cant approve this , this bypass entirely the renewal flow please provide a rationale for this |
|
@gcutrini following up on the earlier request for a rationale: the current PR description explains why the resolver has to live inside What's still missing is the actual concern raised: when
|
uicore fetches the access token internally, and a consumer has no way to supply one. Several uicore modules call getAccessToken, so the source must be injectable inside uicore rather than overridden by the consumer.
Add setAccessTokenResolver to security/methods: when a resolver is registered, getAccessToken delegates to it; otherwise the built-in flow is unchanged. Passing a non-function resets to the built-in.
The resolver is module-level state, so also externalize security/methods in the webpack build. That way every uicore lib entry shares one methods instance and sees the registered resolver; otherwise an entry that inlines its own copy keeps its own null resolver and ignores it.