Skip to content

Silence warning from upgrade to django-oauth-toolkit 3.4.1 - #895

Closed
cigamit wants to merge 1 commit into
mainfrom
d.o.t_3.4.1_warning
Closed

cigamit wants to merge 1 commit into
mainfrom
d.o.t_3.4.1_warning

Conversation

@cigamit

@cigamit cigamit commented Sep 8, 2026 •

Copy link
Copy Markdown
Collaborator

After the upgrade, this is displayed over and over in the logs.

System check identified some issues:

WARNINGS:
?: (oauth2_provider.W011) The configured AccessToken model ('main.OAuth2AccessToken') and RefreshToken model ('oauth2_provider.RefreshToken') are defined in different apps, but they reference each other with a circular foreign key.

HINT: Swap the AccessToken and RefreshToken models into the same app -- e.g. point OAUTH2_PROVIDER_ACCESS_TOKEN_MODEL and OAUTH2_PROVIDER_REFRESH_TOKEN_MODEL at models in one app. The IDToken model is usually customized alongside them. See 'Extending the token models' in the advanced topics documentation.

What changed.

PR #822, merged today, moved django-oauth-toolkit from 3.3.0 to 3.4.1. Release 3.4.1 (2026-08-21) added a brand-new system check, W011, that warns when the swapped AccessToken and RefreshToken models live in different Django apps. Our configuration has done exactly that since the initial import: the access token is swapped to a custom model in the main app, while the refresh token and ID token stay in the toolkit's own app, at defaults.py:526-529. So the configuration is old and unchanged. Only the check is new.

Why it repeats.

Every awx-manage command runs system checks at startup. The container launches around eight of them under supervisord, plus migrate and collectstatic, so the same warning is printed once per process.

Is anything actually broken?

No. The toolkit's own docstring for the check says the real hazard is Django being unable to order the initial migration for a cross-app circular foreign key. Our migration graph has already solved that by hand: the main-app migrations declare swappable dependencies on the refresh and ID token models, most recently in 0213_oauth2accesstoken_resource_and_more.py:14-15. The check runs awx-manage check clean with exit code 0, migrations apply, and the OAuth tests in PR #822 pass. The check's own comment says the warning exists because the setup is "almost always a mistake rather than an intention." Here it is intentional and long-established.

@cigamit
cigamit requested a review from TheWitness September 8, 2026 02:56
@cigamit cigamit self-assigned this Sep 8, 2026
Copilot AI lite review requested due to automatic review settings September 8, 2026 02:56
@cigamit cigamit added the bug Something isn't working label Sep 8, 2026

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

The change is a small, well-scoped settings adjustment that addresses log noise without altering runtime behavior, and the stated migration dependency rationale is supported by existing swappable_dependency usage in awx.main migrations.

Pull request overview

This PR updates Ascender’s default Django settings to suppress the new django-oauth-toolkit system check warning oauth2_provider.W011, which was introduced in django-oauth-toolkit 3.4.1 and is repeatedly emitted due to Ascender’s intentional split between a swapped AccessToken model in awx.main and the stock RefreshToken model in oauth2_provider.

Changes:

  • Adds oauth2_provider.W011 to SILENCED_SYSTEM_CHECKS to prevent noisy repeated log warnings.
  • Documents why the warning is considered non-actionable for this codebase (manual migration dependencies already exist via swappable_dependency).
File summaries
File Description
awx/settings/defaults.py Silences oauth2_provider.W011 and adds rationale explaining why the warning is expected/benign in Ascender.
Review details
  • Files reviewed: 1/1 changed files
  • Comments generated: 0
  • Review effort level: Lite

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@blaipr

blaipr commented Sep 8, 2026 •

Copy link
Copy Markdown
Contributor

#897 is the proper fix for this: it moves the refresh and ID token models into main so the check has nothing left to report, rather than hiding the message. awx-manage check comes out clean with no entry in SILENCED_SYSTEM_CHECKS.

Your read of the situation is right, though: nothing is broken, the dependencies are declared by hand, and the check fires on a setup that is intentional here.

They are mutually exclusive. Yours is one line and no risk; mine is two models, eight call sites and a migration that touches the token tables on upgrade.

One thing worth knowing either way: once a model is swapped out Django skips operations on it, so DOT's later migrations never reach the old table. On existing installs oauth2_provider_refreshtoken is missing token_checksum (its 0015) and resource (its 0018). Invisible unless the models ever move.

#897 is verified on a fresh database and on a copy of a real one with 71 access tokens and a live refresh token: rows preserved, old tables dropped, both keys inside main, 3986 tests passing.

@cigamit

cigamit commented Sep 8, 2026

Copy link
Copy Markdown
Collaborator Author

Closing this in favor of the full fix, even though its as painful as I thought it would be.

@cigamit cigamit closed this Sep 8, 2026
@cigamit
cigamit deleted the d.o.t_3.4.1_warning branch October 1, 2026 14:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working

Development

Successfully merging this pull request may close these issues.

3 participants