Skip to content

FormBuilder: settings for token timeout and redirection url - #36291

Open
colemanw wants to merge 1 commit into
civicrm:masterfrom
colemanw:auth_redirect
Open

FormBuilder: settings for token timeout and redirection url#36291
colemanw wants to merge 1 commit into
civicrm:masterfrom
colemanw:auth_redirect

Conversation

@colemanw

@colemanw colemanw commented Jul 22, 2026

Copy link
Copy Markdown
Member

Overview

Allow authentication token validity period to be set on form and redirect to an alternative URL if authentication token fails.

Rebase of PR #26983 with additional unit tests added to address feedback from that PR.

Screenshot 2026-07-21 at 8 23 45 PM

@civibot

civibot Bot commented Jul 22, 2026

Copy link
Copy Markdown

🤖 Thank you for contributing to CiviCRM! ❤️ We will need to test and review this PR. 👷

Introduction for new contributors...
  • If this is your first PR, an admin will greenlight automated testing with the command ok to test or add to whitelist.
  • A series of tests will automatically run. You can see the results at the bottom of this page (if there are any problems, it will include a link to see what went wrong).
  • A demo site will be built where anyone can try out a version of CiviCRM that includes your changes.
  • If this process needs to be repeated, an admin will issue the command test this please to rerun tests and build a new demo site.
  • Before this PR can be merged, it needs to be reviewed. Please keep in mind that reviewers are volunteers, and their response time can vary from a few hours to a few weeks depending on their availability and their knowledge of this particular part of CiviCRM.
  • A great way to speed up this process is to "trade reviews" with someone - find an open PR that you feel able to review, and leave a comment like "I'm reviewing this now, could you please review mine?" (include a link to yours). You don't have to wait for a response to get started (and you don't have to stop at one!) the more you review, the faster this process goes for everyone 😄
  • To ensure that you are credited properly in the final release notes, please add yourself to contributor-key.yml
  • For more information about contributing, see CONTRIBUTING.md.
PR commands & links...
  • /rebase <branch-name> will rebase your branch and change the base of the PR.
  • /squash will combine all commits (keeping only the first commit messsage).
  • /port <branch-name> will create a copy of this PR against a different branch.
  • /lintroll will automatically fix linting errors, amending commits as needed.
  • retest this please will rerun the tests and rebuild the demo site.
  • 📖 Review standards
  • 🗒️ Review template (brief or verbose)

➡️ Online demo of this PR 🔗

@aydun

aydun commented Jul 22, 2026

Copy link
Copy Markdown
Contributor

Thanks for resurrecting this one @colemanw

@mattwire

mattwire commented Aug 3, 2026

Copy link
Copy Markdown
Contributor

@colemanw So if you later change the timeout/expiry on the form it will apply retrospectively? That seems like a good idea as it effectively gives you a revocation path.

@colemanw

colemanw commented Aug 3, 2026

Copy link
Copy Markdown
Member Author

No, it will not apply retrospectively.
When Tokens::createUrl() generates the token URL (_aff=Bearer <jwt>), the expiration timestamp (exp) is calculated at the moment of URL creation (time() + (timeout * 86400)) and signed inside the JWT payload.

Allow authentication token validity period to be set on form and redirect to an alternative URL if authentication token fails.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants