AshAuthentication. Oauth2Server. ClientResource
(ash_authentication_oauth2_server v0.3.1)
Copy Markdown
View Source
Resource extension for an OAuth2 client resource.
Its purpose is garbage-collecting Client ID Metadata Document (CIMD)
clients. A CIMD client is resolved and upserted (keyed by cimd_url)
whenever an unfamiliar URL client_id reaches /authorize, so without
a bound the client table grows one row per distinct URL ever seen. This
extension adds an auto-generated :expunge_expired destroy action that
removes CIMD client rows whose last_used_at is older than
cimd_client_ttl, and reuses (or auto-generates) a :touch update
action the token and authorize paths call to keep active clients from
being collected.
Only rows with a non-nil cimd_url are ever removed; ordinary
(registered) clients are untouched.
Usage
use Ash.Resource,
extensions: [AshAuthentication.Oauth2Server.ClientResource],
...
oauth2_server do
expunge_interval 24
cimd_client_ttl 2_592_000
endThe resource must have cimd_url and last_used_at attributes (the
installer scaffolds both). Removal is driven by
AshAuthentication.Oauth2Server.Expunger, started by
AshAuthentication.Oauth2Server.Supervisor.
Summary
Functions
Bulk-destroy CIMD client rows (those with a cimd_url) whose
last_used_at is older than the configured cimd_client_ttl.
Refresh a CIMD client's last_used_at to now, so that an actively-used
client is not collected by expunge_expired/2. Best-effort; a failure
is logged, never raised.
Functions
@spec expunge_expired( Ash.Resource.t(), keyword() ) :: :ok | {:error, any()}
Bulk-destroy CIMD client rows (those with a cimd_url) whose
last_used_at is older than the configured cimd_client_ttl.
@spec touch_last_used( Ash.Resource.record(), keyword() ) :: :ok
Refresh a CIMD client's last_used_at to now, so that an actively-used
client is not collected by expunge_expired/2. Best-effort; a failure
is logged, never raised.