OIDC: Remove provider access and refresh token from session #782

Signed-off-by: Michael Mayer <michael@photoprism.app>
This commit is contained in:
Michael Mayer 2024-07-08 19:01:53 +02:00
parent 11e5246e33
commit 5546a56183

View file

@ -315,11 +315,7 @@ func OIDCRedirect(router *gin.RouterGroup) {
sess.SetAuthID(user.AuthID)
sess.SetUser(user)
sess.SetGrantType(authn.GrantAuthorizationCode)
// Set identity provider tokens.
sess.IdToken = tokens.IDToken
sess.AccessToken = tokens.AccessToken
sess.RefreshToken = tokens.RefreshToken
// Set session expiration and timeout.
sess.SetExpiresIn(unix.Day)