Skip to content

Custom token rotation expiration time does not work if installation_store is passed at top level #409

Description

@seratch

The option token_rotation_expiration_minutes for customizing token rotation behavior does not work with the following example. While only the customization does not work, token rotation itself works with the default setting (2 hours before rotation).

app = App(
    signing_secret=signing_secret,
    installation_store=DjangoInstallationStore(client_id=client_id),
    oauth_settings=OAuthSettings(
        client_id=client_id,
        client_secret=client_secret,
        scopes=scopes,
        # If you want to test token rotation, enabling the following line will make it easy
        # token_rotation_expiration_minutes=1000000,
        state_store=DjangoOAuthStateStore(expiration_seconds=120),
    ),
)

If you pass installation_store under oauth_settings, your app respects the custom value.

app = App(
    signing_secret=signing_secret,
    oauth_settings=OAuthSettings(
        client_id=client_id,
        client_secret=client_secret,
        scopes=scopes,
        # If you want to test token rotation, enabling the following line will make it easy
        # token_rotation_expiration_minutes=1000000,
        installation_store=DjangoInstallationStore(client_id=client_id),
        state_store=DjangoOAuthStateStore(expiration_seconds=120),
    ),
)

Activity

  1. added this to the 1.8.0 milestone on Jul 16, 2021
  2. added a commit that references this issue on Aug 11, 2021
    0ebcbde
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions