Skip to content

Replace the Scribejava OAuth2 service with a custom implementation #914

Description

@nroduit

Description

OAuth2 / OpenID Connect authentication for DICOMweb and Viewer Hub used the Scribejava library. It brought its own HTTP client and thread pool, duplicated what the built-in JavaNetHttpClient already provides, and made it difficult to apply the request stall guard introduced for #899.

OAuth2ServiceFactory and the authorization-code / client-credentials flows are reimplemented on top of JavaNetHttpClient. Consequences:

  • The scribejava 8.3.3 dependency and its IDEA external annotations are removed.
  • The request stall guard is ported onto the new client: the request half of an exchange is bounded by time without progress (inactivityTimeout) instead of a whole-exchange deadline, so a large STOW-RS send on a slow link is only aborted when bytes stop flowing.
  • The getConnectTimeout / getReadTimeout aliases deprecated in 4.7.3 are removed in favour of getConnectTimeoutMillis / getInactivityTimeoutMillis.
  • Service invalidation on authentication changes (Implement service invalidation for updated authentication methods #896) is preserved.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions