[SECURITY] OAuth: Disable existing tokens when deactivating Application (CVE-2026-101271, Z#23247296)

This commit is contained in:
Raphael Michel
2026-09-29 13:43:52 +02:00
parent 9a989f2eef
commit d5fe5b49df
2 changed files with 60 additions and 2 deletions
+4
View File
@@ -101,6 +101,10 @@ class OAuthAccessToken(AbstractAccessToken):
self.expires = now() - timedelta(hours=1)
self.save(update_fields=['expires'])
def is_valid(self, scopes=None):
# Can maybe be removed after upgrading django-oauth-toolkit to 3.4.1
return super().is_valid(scopes) and self.application.is_usable(None)
class OAuthRefreshToken(AbstractRefreshToken):
application = models.ForeignKey(