From 5488ea3b7692827b650b682d2db8873fc5d4c273 Mon Sep 17 00:00:00 2001 From: lebaudantoine Date: Thu, 8 Oct 2026 16:40:04 +0200 Subject: [PATCH] =?UTF-8?q?fixup!=20=E2=9C=A8(backend)=20introduce=20a=20t?= =?UTF-8?q?oken=20exchange=20endpoint=20for=20iframe=20embeds?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- src/backend/core/api/viewsets.py | 14 ++++++++------ 1 file changed, 8 insertions(+), 6 deletions(-) diff --git a/src/backend/core/api/viewsets.py b/src/backend/core/api/viewsets.py index 79b876e52..b0ec01522 100644 --- a/src/backend/core/api/viewsets.py +++ b/src/backend/core/api/viewsets.py @@ -211,20 +211,22 @@ class UserViewSet( # Re-check the user at exchange time so that a deactivation after # the transit code was minted is taken into account. + user_id = code_data["user_id"] try: - user = models.User.objects.get(id=code_data["user_id"], is_active=True) + user = models.User.objects.get(id=user_id, is_active=True) except models.User.DoesNotExist as e: raise drf_exceptions.PermissionDenied( "This account can no longer access the application." ) from e + client_id = code_data.get("client_id") if not models.Application.has_active_scope( - code_data.get("client_id"), models.ApplicationScope.USERS_SESSION + client_id, models.ApplicationScope.USERS_SESSION ): logger.warning( "Transit code exchange refused: application '%s' no longer " "holds the '%s' grant", - code_data.get("client_id"), + client_id, models.ApplicationScope.USERS_SESSION, ) raise drf_exceptions.PermissionDenied( @@ -244,7 +246,7 @@ class UserViewSet( user, "user:access", { - "client_id": code_data.get("client_id", "unknown"), + "client_id": client_id or "unknown", "token_type": settings.USER_ACCESS_TOKEN_TYPE_CLAIM, }, ) @@ -252,8 +254,8 @@ class UserViewSet( # Log for auditing logger.info( "User access token issued from transit code: user_id=%s, client_id=%s", - user.id, - code_data.get("client_id", "unknown"), + user_id, + client_id, ) return drf_response.Response(data)