feat: [Badges] support Credly authorization token refresh - #3000
feat: [Badges] support Credly authorization token refresh#3000GlugovGrGlib wants to merge 9 commits into
Conversation
Credly authorization tokens expire 180 days after issuance. Track the token issuance/refresh dates on CredlyOrganization, add a client method that rotates the token via the Credly API, and add the refresh_credly_authorization_tokens management command that warns when a token approaches expiration and rotates it shortly before the deadline. Intended to be run periodically (e.g. daily cron).
|
Thanks for the pull request, @GlugovGrGlib! This repository is currently maintained by Once you've gone through the following steps feel free to tag them in a comment and let them know that your changes are ready for engineering review. 🔘 Get product approvalIf you haven't already, check this list to see if your contribution needs to go through the product review process.
🔘 Provide contextTo help your reviewers and other members of the community understand the purpose and larger context of your changes, feel free to add as much of the following information to the PR description as you can:
🔘 Get a green buildIf one or more checks are failing, continue working on your changes until this is no longer the case and your build turns green. 🔘 Update the status of your PRYour PR is currently marked as a draft. After completing the steps above, update its status by clicking "Ready for Review", or removing "WIP" from the title, as appropriate. Where can I find more information?If you'd like to get more details on all aspects of the review process for open source pull requests (OSPRs), check out the following resources: When can I expect my changes to be merged?Our goal is to get community contributions seen and reviewed as efficiently as possible. However, the amount of time that it takes to review and merge a PR can vary significantly based on factors such as:
💡 As a result it may take up to several weeks or months to complete a review and merge your PR. |
Explain the 180-day token lifetime as part of the Credly setup docs, describe the refresh_credly_authorization_tokens management command, and recommend running it on a daily schedule.
Use the API key term consistently with the rest of the badges docs and the admin UI, bridge it once to Credly's authorization token naming, link the Credly rotation API reference and token lifecycle articles, and add a Tutor variant for the scheduled run.
Expiry is always derived from the latest issuance/rotation moment, so a separate first-issued timestamp adds no behavior. Replace the authorization_token_created_at/authorization_token_updated_at pair with a single authorization_token_issued_at field.
Drop the token naming aside, introduce the command behavior list with a proper lead-in, show Tutor and direct invocations like other pages do, describe the command options as a definition list, and keep the scheduled rotation guidance without scheduler-specific examples.
Description
Credly authorization tokens expire 180 days after issuance (Credly authentication methods). Until now the Credentials service stored a static API key with no record of when it was issued, so once the token expired, badge issuance and template sync silently started failing until an operator manually replaced the key.
This PR adds token lifetime tracking and automatic rotation:
CredlyOrganizationgains anauthorization_token_issued_atfield (set on issuance and every rotation), plusauthorization_token_expires_atandauthorization_token_days_until_expiryhelpers (180-day lifetime).CredlyAPIClient.rotate_authorization_token()calls Credly'sPOST /v1/organizations/{organization_id}/authorization_tokens/rotateendpoint (API reference), persists the new token and refresh timestamps, and adopts the new token for subsequent requests.refresh_credly_authorization_tokensmanagement command, intended for a periodic (e.g. daily) run:--organization_id <uuid>to limit scope and--forceto rotate immediately;Fixes #2984
Testing
pytest credentials/apps/badges/tests/— 145 passed.makemigrations badges --check— no missing migrations.Remaining work (draft)
data.token) against a Credly sandbox — the public docs do not document the response payload, and rotation invalidates the old token immediately.BADGES_CONFIG["credly"]["ORGANIZATIONS"](their DBapi_keyis blank; rotation would fail and could invalidate the settings-provided token).docs/sharing/badges/(operator docs in the Credly configuration page, plus a quickstart note).JavaScript tests
No JavaScript changes in this PR — Karma checklist not applicable.