fixup! ✨(backend) introduce a token exchange endpoint for iframe embeds

This commit is contained in:
lebaudantoine
2026-10-08 16:40:04 +02:00
parent 5c99106150
commit 5488ea3b76
+8 -6
View File
@@ -211,20 +211,22 @@ class UserViewSet(
# Re-check the user at exchange time so that a deactivation after
# the transit code was minted is taken into account.
user_id = code_data["user_id"]
try:
user = models.User.objects.get(id=code_data["user_id"], is_active=True)
user = models.User.objects.get(id=user_id, is_active=True)
except models.User.DoesNotExist as e:
raise drf_exceptions.PermissionDenied(
"This account can no longer access the application."
) from e
client_id = code_data.get("client_id")
if not models.Application.has_active_scope(
code_data.get("client_id"), models.ApplicationScope.USERS_SESSION
client_id, models.ApplicationScope.USERS_SESSION
):
logger.warning(
"Transit code exchange refused: application '%s' no longer "
"holds the '%s' grant",
code_data.get("client_id"),
client_id,
models.ApplicationScope.USERS_SESSION,
)
raise drf_exceptions.PermissionDenied(
@@ -244,7 +246,7 @@ class UserViewSet(
user,
"user:access",
{
"client_id": code_data.get("client_id", "unknown"),
"client_id": client_id or "unknown",
"token_type": settings.USER_ACCESS_TOKEN_TYPE_CLAIM,
},
)
@@ -252,8 +254,8 @@ class UserViewSet(
# Log for auditing
logger.info(
"User access token issued from transit code: user_id=%s, client_id=%s",
user.id,
code_data.get("client_id", "unknown"),
user_id,
client_id,
)
return drf_response.Response(data)