Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Fix Oauth token refresh & Quarkus Log exception #75

Merged
merged 6 commits into from
May 15, 2024
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 2 additions & 0 deletions docs/modules/ROOT/pages/index.adoc
Original file line number Diff line number Diff line change
Expand Up @@ -123,6 +123,7 @@ quarkus.solace.vpn=default
quarkus.solace.authentication.scheme=AUTHENTICATION_SCHEME_OAUTH2
quarkus.solace.oidc.client-name=solace // client name provided in oidc client config below
quarkus.solace.oidc.refresh.interval=50s // Refresh interval should be less than access token expiry time. Otherwise extension will fail to update access token in solace session.
quarkus.solace.oidc.refresh.timeout=10s // Token Refresh API timeout. Default is set to 10 seconds.

quarkus.oidc-client.solace.auth-server-url=http://localhost:7777/auth/realms/master
quarkus.oidc-client.solace.client-id=<client-id>
Expand All @@ -142,6 +143,7 @@ quarkus.solace.tls.trust-store-type=
quarkus.solace.tls.trust-store-password=
quarkus.solace.oidc.client-name=solace // client name provided in oidc client config below
quarkus.solace.oidc.refresh.interval=50s // Refresh interval should be less than access token expiry time. Otherwise extension will fail to update access token in solace session.
quarkus.solace.oidc.refresh.timeout=10s // Token Refresh API timeout. Default is set to 10 seconds.

quarkus.oidc-client.solace.auth-server-url=http://localhost:7777/auth/realms/master
quarkus.oidc-client.solace.client-id=<client-id>
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -25,6 +25,9 @@ public class OidcProvider {
@ConfigProperty(name = "quarkus.solace.oidc.refresh.interval", defaultValue = "60s")
Duration duration;

@ConfigProperty(name = "quarkus.solace.oidc.refresh.timeout", defaultValue = "10s")
Duration refreshTimeout;

@ConfigProperty(name = "quarkus.solace.oidc.client-name")
Optional<String> oidcClientName;

Expand All @@ -43,17 +46,17 @@ Tokens getToken() {
void init(MessagingService service) {
OidcClient client = getClient();
Multi.createFrom().ticks().every(duration)
.onOverflow().drop()
.emitOn(Infrastructure.getDefaultWorkerPool())
.filter(x -> lastToken == null
|| lastToken.getRefreshTokenTimeSkew() == null
|| lastToken.isAccessTokenWithinRefreshInterval())
.call(() -> {
if (lastToken != null && lastToken.getRefreshToken() != null) {
if (lastToken != null && lastToken.getRefreshToken() != null
&& lastToken.isAccessTokenWithinRefreshInterval()) {
Log.info("Refreshing access token for Solace connection");
return client.refreshTokens(lastToken.getRefreshToken()).invoke(tokens -> lastToken = tokens);
return client.refreshTokens(lastToken.getRefreshToken()).invoke(tokens -> lastToken = tokens).ifNoItem()
.after(refreshTimeout).fail();
} else {
Log.info("Acquiring access token for Solace connection");
return client.getTokens().invoke(tokens -> lastToken = tokens);
return client.getTokens().invoke(tokens -> lastToken = tokens).ifNoItem().after(refreshTimeout).fail();
}
})
.onFailure().call(t -> {
Expand All @@ -64,6 +67,7 @@ void init(MessagingService service) {
.subscribe().with(x -> {
if (service.isConnected()) {
service.updateProperty(SCHEME_OAUTH2_ACCESS_TOKEN, lastToken.getAccessToken());
Log.info("Updated Solace Session with latest access token");
} else {
Log.info("Solace service is not connected, cannot update access token without valid connection");
}
Expand All @@ -75,8 +79,4 @@ OidcClient getClient() {
.orElseGet(clients::getClient);
}

public Tokens getLastToken() {
return lastToken;
}

}
}
Original file line number Diff line number Diff line change
@@ -1,5 +1,7 @@
package com.solace.quarkus.runtime;

import static com.solace.messaging.config.SolaceProperties.AuthenticationProperties.SCHEME_OAUTH2_ACCESS_TOKEN;

import java.util.Map;
import java.util.Properties;
import java.util.function.Function;
Expand All @@ -14,6 +16,7 @@
import com.solace.quarkus.MessagingServiceClientCustomizer;

import io.quarkus.arc.SyntheticCreationalContext;
import io.quarkus.logging.Log;
import io.quarkus.runtime.ShutdownContext;
import io.quarkus.runtime.annotations.Recorder;

Expand Down Expand Up @@ -71,6 +74,14 @@ public MessagingService apply(SyntheticCreationalContext<MessagingService> conte
}
});

// Update access token on reconnect to make sure invalid token is not sent. This can happen when a reconnection happens event before scheduled token expiry.
service.addReconnectionAttemptListener(serviceEvent -> {
Log.info("Reconnecting to Solace broker due to " + serviceEvent.getMessage());
if (oidcProvider != null && authScheme != null && "AUTHENTICATION_SCHEME_OAUTH2".equals(authScheme)) {
service.updateProperty(SCHEME_OAUTH2_ACCESS_TOKEN, oidcProvider.getToken().getAccessToken());
}
});

return service.connect();
}
};
Expand Down
Empty file.
Loading