Detect revoked SSO tokens

Bug #624065 reported by Michael Vogt
22
This bug affects 4 people
Affects Status Importance Assigned to Milestone
Ubuntu Single Sign On Client
Won't Fix
Medium
Ubuntu One Client Engineering team
ubuntu-sso-client (Ubuntu)
Won't Fix
Medium
Ubuntu One Client Engineering team

Bug Description

Hi,

when the ubuntu-sso-client has a token it would be great if it could check if that token is still valid and if
not request a new token. If its not done in the sso client it will be code that needs to be written in all apps
that use the client to ensure that the token in use is valid and the user has not revoked it since.

Thanks,
 Michael

Tags: natty
summary: - Please detect revoked SSO tokens
+ Detect revoked SSO tokens
Changed in ubuntu-sso-client:
status: New → Confirmed
assignee: nobody → Naty Bidart (nataliabidart)
importance: Undecided → Medium
tags: added: desktop+ u1-natty
Changed in ubuntu-sso-client:
status: Confirmed → Triaged
assignee: Naty Bidart (nataliabidart) → Ubuntu One Desktop+ team (ubuntuone-desktop+)
Revision history for this message
Michael Vogt (mvo) wrote :

I added a ubuntu task as I believe a persistent oneconf sync failure I got during the maverick cycle is caused by this issue (the token was revoked but the desktopcouch based tools assumed that if it comes from ubuntu-sso-client its valid and did not manage to recover).

Changed in ubuntu-sso-client (Ubuntu):
status: New → Triaged
importance: Undecided → Medium
assignee: nobody → Ubuntu One Desktop+ team (ubuntuone-desktop+)
Revision history for this message
Natalia Bidart (nataliabidart) wrote :

Michael and rest,

I've been thinking about this issue and I realized that if we check the validity of the tokens on each request, this will imply that the token retrieval will be network dependent, and we want to avoid that.

We may make public the validate_user method call through DBus. That way, any app is responsible to validate the token if they consider is necessary and if the know they have net conn.

tags: removed: desktop+
Leo Arias (elopio)
tags: added: natty
removed: u1-natty
Changed in ubuntu-sso-client:
status: Triaged → Won't Fix
Changed in ubuntu-sso-client (Ubuntu):
status: Triaged → Won't Fix
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.