Skip to content

Commit 930f2fb

Browse files
Merge pull request #320 from supertokens/session-fix
fix: session fix
2 parents 7530535 + 9c30432 commit 930f2fb

File tree

5 files changed

+65
-16
lines changed

5 files changed

+65
-16
lines changed

CHANGELOG.md

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -7,6 +7,11 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0
77

88
## [unreleased]
99

10+
## [0.12.10] - 2023-07-31
11+
12+
- Fixes error handling with regenerate access token when the access token of the session is revoked.
13+
- Fixes payload in get session when the access token version <= 2
14+
1015
## [0.12.9] - 2023-07-26
1116

1217
- Fixes an issue where updating the user's password from the user management dashboard would result in a crash when using the thirdpartyemailpassword recipe (https://github.com/supertokens/supertokens-golang/issues/311)

recipe/session/recipeImplementation.go

Lines changed: 17 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -20,14 +20,15 @@ import (
2020
"encoding/json"
2121
defaultErrors "errors"
2222
"fmt"
23+
"reflect"
24+
"sync"
25+
"time"
26+
2327
"github.com/MicahParks/keyfunc"
2428
"github.com/supertokens/supertokens-golang/recipe/session/claims"
2529
"github.com/supertokens/supertokens-golang/recipe/session/errors"
2630
"github.com/supertokens/supertokens-golang/recipe/session/sessmodels"
2731
"github.com/supertokens/supertokens-golang/supertokens"
28-
"reflect"
29-
"sync"
30-
"time"
3132
)
3233

3334
var protectedProps = []string{
@@ -126,7 +127,8 @@ func getJWKS() (*keyfunc.JWKS, error) {
126127
return nil, lastError
127128
}
128129

129-
/**
130+
/*
131+
*
130132
This function fetches all JWKs from the first available core instance. This combines the other JWKS functions to become
131133
error resistant.
132134
@@ -251,16 +253,20 @@ func MakeRecipeImplementation(querier supertokens.Querier, config sessmodels.Typ
251253
supertokens.LogDebugMessage("getSession: Success!")
252254
var payload map[string]interface{}
253255

254-
if !reflect.DeepEqual(response.AccessToken, sessmodels.CreateOrRefreshAPIResponseToken{}) {
255-
parsedToken, parseErr := ParseJWTWithoutSignatureVerification(response.AccessToken.Token)
256+
if accessToken.Version >= 3 {
257+
if !reflect.DeepEqual(response.AccessToken, sessmodels.CreateOrRefreshAPIResponseToken{}) {
258+
parsedToken, parseErr := ParseJWTWithoutSignatureVerification(response.AccessToken.Token)
256259

257-
if parseErr != nil {
258-
return nil, parseErr
259-
}
260+
if parseErr != nil {
261+
return nil, parseErr
262+
}
260263

261-
payload = parsedToken.Payload
264+
payload = parsedToken.Payload
265+
} else {
266+
payload = accessToken.Payload
267+
}
262268
} else {
263-
payload = accessToken.Payload
269+
payload = response.Session.UserDataInAccessToken
264270
}
265271

266272
accessTokenStringForSession := *accessTokenString

recipe/session/session.go

Lines changed: 3 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -157,14 +157,13 @@ func newSessionContainer(config sessmodels.TypeNormalisedInput, session *Session
157157
}
158158
}
159159

160-
querier, err := supertokens.GetNewQuerierInstanceOrThrowError("")
160+
response, err := (*session.recipeImpl.RegenerateAccessToken)(sessionContainer.GetAccessToken(), &accessTokenPayload, userContext)
161+
161162
if err != nil {
162163
return err
163164
}
164165

165-
response, err := regenerateAccessTokenHelper(*querier, &accessTokenPayload, sessionContainer.GetAccessToken())
166-
167-
if err != nil {
166+
if response == nil {
168167
supertokens.LogDebugMessage(fmt.Sprintf("MergeIntoAccessTokenPayloadWithContext: Returning UnauthorizedError because we could not regenerate the session - %s", err))
169168
return errors.UnauthorizedError{
170169
Msg: errors.UnauthorizedErrorStr,

recipe/session/session_test.go

Lines changed: 39 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -26,6 +26,7 @@ import (
2626
"time"
2727

2828
"github.com/stretchr/testify/assert"
29+
"github.com/supertokens/supertokens-golang/recipe/session/errors"
2930
"github.com/supertokens/supertokens-golang/recipe/session/sessmodels"
3031
"github.com/supertokens/supertokens-golang/supertokens"
3132
"github.com/supertokens/supertokens-golang/test/unittesting"
@@ -2075,6 +2076,44 @@ func TestThatGetSessionThrowsWIthDynamicKeysIfSessionWasCreatedWithStaticKeys(t
20752076
assert.Equal(t, err.Error(), "The access token doesn't match the useDynamicAccessTokenSigningKey setting")
20762077
}
20772078

2079+
func TestThatRevokedAccessTokenThrowsUnauthorisedErrorWhenRegenerateTokenIsCalled(t *testing.T) {
2080+
configValue := supertokens.TypeInput{
2081+
Supertokens: &supertokens.ConnectionInfo{
2082+
ConnectionURI: "http://localhost:8080",
2083+
},
2084+
AppInfo: supertokens.AppInfo{
2085+
APIDomain: "api.supertokens.io",
2086+
AppName: "SuperTokens",
2087+
WebsiteDomain: "supertokens.io",
2088+
},
2089+
RecipeList: []supertokens.Recipe{
2090+
Init(nil),
2091+
},
2092+
}
2093+
2094+
BeforeEach()
2095+
unittesting.StartUpST("localhost", "8080")
2096+
defer AfterEach()
2097+
2098+
err := supertokens.Init(configValue)
2099+
if err != nil {
2100+
t.Error(err.Error())
2101+
}
2102+
sessionContainer, err := CreateNewSessionWithoutRequestResponse("testing-user", map[string]interface{}{}, map[string]interface{}{}, nil)
2103+
if err != nil {
2104+
t.Error(err.Error())
2105+
}
2106+
_, err = RevokeSession(sessionContainer.GetHandle())
2107+
if err != nil {
2108+
t.Error(err.Error())
2109+
}
2110+
2111+
err = sessionContainer.MergeIntoAccessTokenPayload(map[string]interface{}{"key": "value"})
2112+
assert.NotNil(t, err)
2113+
_, ok := err.(errors.UnauthorizedError)
2114+
assert.True(t, ok)
2115+
}
2116+
20782117
func jwksLockTestRoutine(t *testing.T, shouldStop *bool, index int, group *sync.WaitGroup, doPost func([]string)) {
20792118
jwks, err := GetCombinedJWKS()
20802119
if err != nil {

supertokens/constants.go

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -21,7 +21,7 @@ const (
2121
)
2222

2323
// VERSION current version of the lib
24-
const VERSION = "0.12.9"
24+
const VERSION = "0.12.10"
2525

2626
var (
2727
cdiSupported = []string{"2.21"}

0 commit comments

Comments
 (0)