Skip to content

[ENG-12141] - revoke access and remove token when user remove ORCID connection - #11907

Open
Vlad0n20 wants to merge 3 commits into
CenterForOpenScience:feature/pbs-26-19from
Vlad0n20:fix/ENG-12141
Open

Vlad0n20 wants to merge 3 commits into
CenterForOpenScience:feature/pbs-26-19from
Vlad0n20:fix/ENG-12141

Conversation

@Vlad0n20

@Vlad0n20 Vlad0n20 commented Sep 9, 2026 •

Copy link
Copy Markdown
Contributor

Ticket

Purpose

Changes

Side Effects

QE Notes

CE Notes

Documentation

@cslzchen cslzchen left a comment •

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Please rebase and retarget to latest develop

In addition, fix the ticket link in PR description. Currently, it redirects to the PR itself.

@Vlad0n20
Vlad0n20 changed the base branch from feature/gdpr-delete-orcid-rewrite to develop September 11, 2026 14:16
@Vlad0n20
Vlad0n20 changed the base branch from develop to feature/pbs-26-18 September 14, 2026 13:13
@Ostap-Zherebetskyi

Copy link
Copy Markdown
Collaborator

Please rebase and retarget to latest pbs-26-19

@Vlad0n20
Vlad0n20 changed the base branch from feature/pbs-26-18 to feature/pbs-26-19 September 29, 2026 12:49

@Ostap-Zherebetskyi Ostap-Zherebetskyi left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM ⭐

@cslzchen cslzchen left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Locally tested but find that ORCiD delete is successful even when revoke request failed.

In addition, both identities and tokens are cleared too which left us no tokens to revoke.

We must not allow ORCiD delete to pass (don't clear DB) if revocation fails.

api-1  | [osf.models.user]  INFO: [ORCiD disconnect] Revoking ORCiD Access: user=dk82a, orcid_id=0000-0001-7364-3443
api-1  | >>>> Retrying ...
api-1  | [osf.models.user]  INFO: [ORCiD disconnect] ORCiD Revocation Response: user=dk82a, orcid_id=0000-0001-7364-3443, status_code=401, response_text={"error_description":"Client authentication failed","error":"invalid_client"}
api-1  | [osf.models.user]  ERROR: [ORCiD disconnect] ORCiD Revocation Failed: user=dk82a, orcid_id=0000-0001-7364-3443, error=401 Client Error: Unauthorized for url: https://orcid.org/oauth/revoke
api-1  | [framework.sentry]  WARNING: Sentry called to log message, but is not active: [ORCiD disconnect] ORCiD Revocation Failed: user=dk82a, orcid_id=0000-0001-7364-3443, error=401 Client Error: Unauthorized for url: https://orcid.org/oauth/revoke. Extra data: None
api-1  | [framework.sentry]  WARNING: Sentry called to log exception, but is not active: 401 Client Error: Unauthorized for url: https://orcid.org/oauth/revoke
api-1  | [02/Oct/2026 17:16:41] "DELETE /v2/users/me/settings/identities/ORCID/ HTTP/1.1" 204 0

Finally, not sure how requests_retry_session works since it is not widely used in our code base. Can you take a look and confirm this retry works as expected. I didn't see 3 retries as what it suppose to do.

@cslzchen

cslzchen commented Oct 2, 2026

Copy link
Copy Markdown
Collaborator

Another note: please correct your ticket link in PR description so it actually links to the ticket.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants