you still need to update expires_in to trigger the refresh.

#561 · open · 5 comments

View on GitHub ↗

hramrach

why!?!

Comments

JonathanHuot

Hi @hramrach An example of behavior vs expected behavior will help. Any contributions to update the code as well.

hramrach

It says 'Requests-OAuthlib: OAuth for Humans' Why is the human required to track something the machine can track? The chapter https://requests-oauthlib.readthedocs.io/en/latest/oauth2_workflow.html#refreshing-tokens only offers very awkward ways to deal with token refresh. The supposedly recommended one is > [(Third, Recommended) Define automatic token refresh and update](https://requests-oauthlib.readthedocs.io/en/latest/oauth2_workflow.html#id15)[](https://requests-oauthlib.readthedocs.io/en/latest/oauth2_workflow.html#third-recommended-define-automatic-token-refresh-and-update) > > The third and recommended method will automatically fetch refresh tokens and save them. It requires no exception catching and results in clean code. Remember however that you still need to update expires_in to trigger the refresh. This does not really make it automatic at all. The token must have come in a request that has a Date header so it's always clear what expies_in is relative to but the oauth library does not save the relevant data, and requires the user to track it separately.

therealcmj

@hramrach if you are able to write the code to add to the library Jonathan said he's happy to accept it.

hramrach

Turns out not all deployments of the service I am trying to use support oauth so I am not going to use oauthlib for now, and as a result not working on this anytime soon.

injisg

hi @JonathanHuot @hramrach - i have a proposed fix for this https://github.com/requests/requests-oauthlib/pull/565