diff --git a/src/backend/core/api/viewsets.py b/src/backend/core/api/viewsets.py index 79b876e52..b0ec01522 100644 --- a/src/backend/core/api/viewsets.py +++ b/src/backend/core/api/viewsets.py @@ -211,20 +211,22 @@ class UserViewSet( # Re-check the user at exchange time so that a deactivation after # the transit code was minted is taken into account. + user_id = code_data["user_id"] try: - user = models.User.objects.get(id=code_data["user_id"], is_active=True) + user = models.User.objects.get(id=user_id, is_active=True) except models.User.DoesNotExist as e: raise drf_exceptions.PermissionDenied( "This account can no longer access the application." ) from e + client_id = code_data.get("client_id") if not models.Application.has_active_scope( - code_data.get("client_id"), models.ApplicationScope.USERS_SESSION + client_id, models.ApplicationScope.USERS_SESSION ): logger.warning( "Transit code exchange refused: application '%s' no longer " "holds the '%s' grant", - code_data.get("client_id"), + client_id, models.ApplicationScope.USERS_SESSION, ) raise drf_exceptions.PermissionDenied( @@ -244,7 +246,7 @@ class UserViewSet( user, "user:access", { - "client_id": code_data.get("client_id", "unknown"), + "client_id": client_id or "unknown", "token_type": settings.USER_ACCESS_TOKEN_TYPE_CLAIM, }, ) @@ -252,8 +254,8 @@ class UserViewSet( # Log for auditing logger.info( "User access token issued from transit code: user_id=%s, client_id=%s", - user.id, - code_data.get("client_id", "unknown"), + user_id, + client_id, ) return drf_response.Response(data)