MDL-58128 oauth2: Add a scheduled task for refresh
We need to make sure our refresh tokens do not expire. We run a scheduled task to update the refresh token once per hour. Part of MDL-58220
This commit is contained in:
@@ -795,6 +795,8 @@ $string['notifyloginthreshold'] = 'Threshold for email notifications';
|
||||
$string['notloggedinroleid'] = 'Role for visitors';
|
||||
$string['numberofmissingstrings'] = 'Number of missing strings: {$a}';
|
||||
$string['numberofstrings'] = 'Total number of strings: {$a->strings}<br />Missing: {$a->missing} ({$a->missingpercent} %)';
|
||||
$string['oauthrefreshtokenexpired'] = 'The refresh token for one of the OAuth services {$a->issuer} on your site {$a->siteurl} has expired. This will limit the functionality of any plugins that use this service. To fix this issue, visit the OAuth 2 Services configuration page and click on the "Connect system account" icon in the table row for this service. Be sure to login using the same service account for the OAuth system each time.';
|
||||
$string['oauthrefreshtokenexpiredshort'] = 'OAuth refresh token expired for {$a->issuer} on your site {$a->siteurl}.';
|
||||
$string['onlynoreply'] = 'Only when from a no-reply address';
|
||||
$string['opcacherecommended'] = 'PHP opcode caching improves performance and lowers memory requirements, OPcache extension is recommended and fully supported.';
|
||||
$string['opensslrecommended'] = 'Installing the optional OpenSSL library is highly recommended -- it enables Moodle Networking functionality.';
|
||||
@@ -1094,6 +1096,7 @@ $string['taskpasswordresetcleanup'] = 'Cleanup password reset attempts';
|
||||
$string['taskplagiarismcron'] = 'Background processing for legacy cron in plagiarism plugins';
|
||||
$string['taskportfoliocron'] = 'Background processing for portfolio plugins';
|
||||
$string['taskquestioncron'] = 'Background processing for question engine';
|
||||
$string['taskrefreshoauthtokens'] = 'Refresh OAuth tokens for service accounts';
|
||||
$string['taskregistrationcron'] = 'Site registration';
|
||||
$string['tasksendfailedloginnotifications'] = 'Send failed login notifications';
|
||||
$string['tasksendnewuserpasswords'] = 'Send new user passwords';
|
||||
|
||||
@@ -0,0 +1,88 @@
|
||||
<?php
|
||||
// This file is part of Moodle - http://moodle.org/
|
||||
//
|
||||
// Moodle is free software: you can redistribute it and/or modify
|
||||
// it under the terms of the GNU General Public License as published by
|
||||
// the Free Software Foundation, either version 3 of the License, or
|
||||
// (at your option) any later version.
|
||||
//
|
||||
// Moodle is distributed in the hope that it will be useful,
|
||||
// but WITHOUT ANY WARRANTY; without even the implied warranty of
|
||||
// MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
||||
// GNU General Public License for more details.
|
||||
//
|
||||
// You should have received a copy of the GNU General Public License
|
||||
// along with Moodle. If not, see <http://www.gnu.org/licenses/>.
|
||||
|
||||
/**
|
||||
* A scheduled task.
|
||||
*
|
||||
* @package core
|
||||
* @copyright 2017 Damyon Wiese
|
||||
* @license http://www.gnu.org/copyleft/gpl.html GNU GPL v3 or later
|
||||
*/
|
||||
namespace core\oauth2;
|
||||
|
||||
use \core\task\scheduled_task;
|
||||
|
||||
/**
|
||||
* Simple task to delete old messaging records.
|
||||
*/
|
||||
class refresh_system_tokens_task extends scheduled_task {
|
||||
|
||||
/**
|
||||
* Get a descriptive name for this task (shown to admins).
|
||||
*
|
||||
* @return string
|
||||
*/
|
||||
public function get_name() {
|
||||
return get_string('taskrefreshsystemtokens', 'admin');
|
||||
}
|
||||
|
||||
/**
|
||||
* Notify admins when an OAuth refresh token expires. Should not happen if cron is running regularly.
|
||||
* @param \core\oauth2\issuer $issuer
|
||||
*/
|
||||
protected function notify_admins(\core\oauth2\issuer $issuer) {
|
||||
$admins = get_admins();
|
||||
|
||||
if (empty($admins)) {
|
||||
return;
|
||||
}
|
||||
foreach ($admins as $admin) {
|
||||
$strparams = ['siteurl' => $CFG->wwwroot, 'issuer' => $issuer->get('name')];
|
||||
$long = get_string('oauthrefreshtokenexpired', 'core_admin', $strparams);
|
||||
$short = get_string('oauthrefreshtokenexpiredshort', 'core_admin', $strparams);
|
||||
$message = new \core\message\message();
|
||||
$message->courseid = SITEID;
|
||||
$message->component = 'moodle';
|
||||
$message->name = 'oauthrefreshtokenexpired';
|
||||
$message->userfrom = core\user::get_noreply_user();
|
||||
$message->userto = $admin;
|
||||
$message->subject = $short;
|
||||
$message->fullmessage = $long;
|
||||
$message->fullmessageformat = FORMAT_PLAIN;
|
||||
$message->fullmessagehtml = $long;
|
||||
$message->smallmessage = $short;
|
||||
$message->notification = 1;
|
||||
message_send($message);
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
/**
|
||||
* Do the job.
|
||||
* Throw exceptions on errors (the job will be retried).
|
||||
*/
|
||||
public function execute() {
|
||||
$issuers = \core\oauth2\api::get_all_issuers();
|
||||
foreach ($issuers as $issuer) {
|
||||
if ($issuer->is_system_account_connected()) {
|
||||
if (!\core\oauth2\api::get_system_oauth_client($issuer)) {
|
||||
$this->notify_admins($issuer);
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
}
|
||||
@@ -347,4 +347,13 @@ $tasks = array(
|
||||
'dayofweek' => '*',
|
||||
'month' => '*'
|
||||
),
|
||||
array(
|
||||
'classname' => 'core\oauth2\refresh_system_tokens_task',
|
||||
'blocking' => 0,
|
||||
'minute' => 'R',
|
||||
'hour' => '*',
|
||||
'day' => '*',
|
||||
'dayofweek' => '*',
|
||||
'month' => '*'
|
||||
),
|
||||
);
|
||||
|
||||
Reference in New Issue
Block a user