Set response header if user needs to reauthenticate to enable Helsinki Profile functionality #1362
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
🛠️ Changelog
X-Keycloak-Refresh-Token-Expired
header in each response if the user's Keycloak refresh token has expired. This token is used for refreshing the user's Helsinki profile tokens, which are used for fetching profile information e.g. for reservation prefill operations. However, if the Keycloak refresh token has expired there is no way to get a new pair (afaik) without reauthenticating (log out and back in again). This response header can be used by the frontend to display a message, or just for debugging purposes.UNSAFE_SKIP_IAT_CLAIM_VALIDATION
for skipping iat validation on Tunnistamo JWTs, which can fail locally if authentication happens too fast.🧪 Test plan
🚧 Dependencies
🎫 Tickets