Re: [OAuth2] Infrastructure for tracking token expiry time - Mailing list pgsql-hackers

From VASUKI M
Subject Re: [OAuth2] Infrastructure for tracking token expiry time
Date
Msg-id CAE2r8H6Tc6F2BM-JqC+gp-HQKCzfHOx02Xj5MmuS-AY4jfN5iw@mail.gmail.com
Whole thread
In response to Re: [OAuth2] Infrastructure for tracking token expiry time  (Zsolt Parragi <zsolt.parragi@percona.com>)
Responses Re: [OAuth2] Infrastructure for tracking token expiry time
List pgsql-hackers
Hi All,

I see the concern about keeping the validator API generic and not implicitly favoring JWT-style providers.
The callback-based approach does seem more flexible, especially for opaque tokens or providers supporting revocation, where validity cannot be represented as a fixed timestamp.
Perhaps one possible direction could be to support both:

An optional expiry timestamp for simple/static cases.

An optional callback (e.g., expired_cb) for dynamic validation.

This would allow JWT-based validators to remain lightweight while enabling more complex providers to implement custom revalidation logic.
If enforcement is planned at statement start, integrating the callback mechanism in the same patch might also clarify the intended semantics.

Best regards,
Vasuki M
C-DAC,Chennai

pgsql-hackers by date:

Previous
From: Soumya S Murali
Date:
Subject: Re: [PATCH] Expose checkpoint reason to completion log messages.
Next
From: Ashutosh Sharma
Date:
Subject: Re: [PATCH] Support automatic sequence replication