11
[Feature] Use OAuth2 access_token and refresh_token
Source: immich-app/immich#15656 · opened by @waclaw66
I have searched the existing feature requests to make sure this is not a duplicate request.
• Yes
The feature
I've noticed that oauth2 usage is quite simplified within Immich. According my investigation it's used only for first authentication and then the internal access token without time restriction is used only. When the access to the app is banned to the user, Immich can be still used without any restriction until logout.
I would suggest to store access_token and refresh_token to the sessions table and use those properly when auth provider tokens are expired.
Platform
• Server
• Web
• Mobile
• Yes
The feature
I've noticed that oauth2 usage is quite simplified within Immich. According my investigation it's used only for first authentication and then the internal access token without time restriction is used only. When the access to the app is banned to the user, Immich can be still used without any restriction until logout.
I would suggest to store access_token and refresh_token to the sessions table and use those properly when auth provider tokens are expired.
Platform
• Server
• Web
• Mobile
No pledges yet. Be the first to back this.
Comments
Similar requests
Support reverse-proxy trusted header authentication (SSO behind Authelia / Authentik / oauth2-proxy)
1 vote · 0 comments
[Feature] Ability to specify SYNC destination album
33 votes · 0 comments
[Feature] Render RAW images with develop settings using XMP sidecar adjustment data
12 votes · 0 comments
[Feature] Utility Geo-Guesser
6 votes · 0 comments
[Feature] Support for Lytro LFR Files in Immich with Optional Advanced Feature Integration
1 vote · 0 comments
No comments yet.