mirror of
https://github.com/go-gitea/gitea.git
synced 2026-08-26 06:43:25 +00:00
feat(user): Personal access tokens can be regenerated (#38907)
Lets users regenerate a personal access token's value in place, keeping its name and scopes, instead of deleting and recreating it. Useful when a token was shared with a third party (e.g. an AI agent) and needs to be invalidated immediately without redoing scope selection. Follows the same pattern already used for OAuth2 application client secrets (`GenerateClientSecret`/`RegenerateSecret`). **Testing**: added a model unit test and a web integration test; manually verified in the running dev server that the old token stops authenticating and the new one works immediately after regenerating. <img width="1040" height="245" alt="image" src="https://github.com/user-attachments/assets/4de0d8b4-1fc4-49cf-a859-95e24d0b2c0a" /> Fixes #38683. --------- Co-authored-by: wxiaoguang <wxiaoguang@gmail.com>
This commit is contained in:
@@ -117,6 +117,46 @@ func TestUpdateAccessToken(t *testing.T) {
|
||||
unittest.AssertExistsAndLoadBean(t, token)
|
||||
}
|
||||
|
||||
func TestRegenerateAccessToken(t *testing.T) {
|
||||
assert.NoError(t, unittest.PrepareTestDatabase())
|
||||
|
||||
const oldToken = "d2c6c1ba3890b309189a8e618c72a162e4efbf36"
|
||||
|
||||
// prime the successful-lookup cache with the old token value, as a real request would
|
||||
before, err := auth_model.GetAccessTokenBySHA(t.Context(), oldToken)
|
||||
assert.NoError(t, err)
|
||||
assert.Equal(t, "Token A", before.Name)
|
||||
|
||||
regenerated, err := auth_model.RegenerateAccessToken(t.Context(), before.ID, before.UID)
|
||||
assert.NoError(t, err)
|
||||
assert.Equal(t, before.ID, regenerated.ID)
|
||||
assert.Equal(t, before.Name, regenerated.Name)
|
||||
assert.Equal(t, before.Scope, regenerated.Scope)
|
||||
assert.NotEqual(t, before.TokenHash, regenerated.TokenHash)
|
||||
assert.NotEmpty(t, regenerated.Token)
|
||||
|
||||
// the old token value must stop authenticating, even though it was cached as successful above
|
||||
_, err = auth_model.GetAccessTokenBySHA(t.Context(), oldToken)
|
||||
assert.Error(t, err)
|
||||
assert.ErrorIs(t, err, util.ErrNotExist)
|
||||
|
||||
// the new token value must authenticate
|
||||
found, err := auth_model.GetAccessTokenBySHA(t.Context(), regenerated.Token)
|
||||
assert.NoError(t, err)
|
||||
assert.Equal(t, before.ID, found.ID)
|
||||
assert.Equal(t, before.UpdatedUnix, found.UpdatedUnix)
|
||||
|
||||
// wrong owner
|
||||
_, err = auth_model.RegenerateAccessToken(t.Context(), before.ID, before.UID+1)
|
||||
assert.Error(t, err)
|
||||
assert.ErrorIs(t, err, util.ErrNotExist)
|
||||
|
||||
// nonexistent token
|
||||
_, err = auth_model.RegenerateAccessToken(t.Context(), 100, 100)
|
||||
assert.Error(t, err)
|
||||
assert.ErrorIs(t, err, util.ErrNotExist)
|
||||
}
|
||||
|
||||
func TestDeleteAccessTokenByID(t *testing.T) {
|
||||
assert.NoError(t, unittest.PrepareTestDatabase())
|
||||
|
||||
|
||||
Reference in New Issue
Block a user