Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
12 changes: 0 additions & 12 deletions containers/api-proxy/anthropic-oidc-token-provider.js
Original file line number Diff line number Diff line change
Expand Up @@ -32,18 +32,6 @@ class AnthropicOidcTokenProvider extends BaseOidcTokenProvider {
this._cachedToken = null;
}

/** @returns {string|null} */
getToken() {
const now = Math.floor(Date.now() / 1000);
if (this._cachedToken && this._expiresAt > now) {
return this._cachedToken;
}
if (!this._refreshInFlight) {
this._scheduleRefresh(0);
}
return null;
}

/**
* Exchange GitHub OIDC JWT for an Anthropic workload identity token.
* @param {string} oidcJwt
Expand Down
12 changes: 0 additions & 12 deletions containers/api-proxy/gcp-oidc-token-provider.js
Original file line number Diff line number Diff line change
Expand Up @@ -51,18 +51,6 @@ class GcpOidcTokenProvider extends BaseOidcTokenProvider {
this._cachedToken = null;
}

/** @returns {string|null} */
getToken() {
const now = Math.floor(Date.now() / 1000);
if (this._cachedToken && this._expiresAt > now) {
return this._cachedToken;
}
if (!this._refreshInFlight) {
this._scheduleRefresh(0);
}
return null;
}

/**
* Exchange GitHub OIDC JWT for a GCP federated access token via STS.
* @param {string} oidcJwt
Expand Down
17 changes: 17 additions & 0 deletions containers/api-proxy/oidc-token-provider-base.js
Original file line number Diff line number Diff line change
Expand Up @@ -68,6 +68,23 @@ class BaseOidcTokenProvider {
return !!(this._getCachedValue() && this._expiresAt > now);
}

/**
* Get the current cached token synchronously.
* Returns null if no valid token is available.
* @returns {unknown|null}
*/
getToken() {
const now = Math.floor(Date.now() / 1000);
const cached = this._getCachedValue();
if (cached && this._expiresAt > now) {
return cached;
}
if (!this._refreshInFlight) {
this._scheduleRefresh(0);
}
return null;
}

shutdown() {
this._isShutdown = true;
if (this._refreshTimer) {
Expand Down
57 changes: 57 additions & 0 deletions containers/api-proxy/oidc-token-provider-base.test.js
Original file line number Diff line number Diff line change
@@ -0,0 +1,57 @@
'use strict';

const { BaseOidcTokenProvider } = require('./oidc-token-provider-base');

class TestOidcTokenProvider extends BaseOidcTokenProvider {
constructor() {
super('test_oidc', {});
this._cachedValue = null;
}

async _doRefresh() {}

_getCachedValue() {
return this._cachedValue;
}

_getInitSuccessLogContext() {
return {};
}

_getInitFailureLogContext() {
return {};
}
}

describe('BaseOidcTokenProvider#getToken', () => {
it('returns cached value when it has not expired', () => {
const provider = new TestOidcTokenProvider();
provider._cachedValue = 'cached-token';
provider._expiresAt = Math.floor(Date.now() / 1000) + 60;

expect(provider.getToken()).toBe('cached-token');
provider.shutdown();
});

it('returns null and schedules refresh when cache is expired', () => {
const provider = new TestOidcTokenProvider();
provider._cachedValue = 'stale-token';
provider._expiresAt = Math.floor(Date.now() / 1000) - 1;
provider._scheduleRefresh = jest.fn();

expect(provider.getToken()).toBeNull();
expect(provider._scheduleRefresh).toHaveBeenCalledWith(0);
provider.shutdown();
});

it('returns null without scheduling refresh when one is already in flight', () => {
const provider = new TestOidcTokenProvider();
provider._cachedValue = null;
provider._refreshInFlight = Promise.resolve();
provider._scheduleRefresh = jest.fn();

expect(provider.getToken()).toBeNull();
expect(provider._scheduleRefresh).not.toHaveBeenCalled();
provider.shutdown();
});
});
17 changes: 0 additions & 17 deletions containers/api-proxy/oidc-token-provider.js
Original file line number Diff line number Diff line change
Expand Up @@ -65,23 +65,6 @@ class OidcTokenProvider extends BaseOidcTokenProvider {
}
}

/**
* Get the current cached token synchronously.
* Returns null if no valid token is available.
* @returns {string|null}
*/
getToken() {
const now = Math.floor(Date.now() / 1000);
if (this._cachedToken && this._expiresAt > now) {
return this._cachedToken;
}
// Token expired and refresh hasn't replaced it — trigger emergency refresh
if (!this._refreshInFlight) {
this._scheduleRefresh(0);
}
return null;
}

/**
* Mint a GitHub OIDC token with the specified audience.
* @returns {Promise<string>} The GitHub-issued JWT
Expand Down
Loading