Repository navigation
Conversation
There was a problem hiding this comment.
🟢 Approval recommended
The change is a small, well-scoped settings adjustment that addresses log noise without altering runtime behavior, and the stated migration dependency rationale is supported by existing swappable_dependency usage in awx.main migrations.
Pull request overview
This PR updates Ascender’s default Django settings to suppress the new django-oauth-toolkit system check warning oauth2_provider.W011, which was introduced in django-oauth-toolkit 3.4.1 and is repeatedly emitted due to Ascender’s intentional split between a swapped AccessToken model in awx.main and the stock RefreshToken model in oauth2_provider.
Changes:
- Adds
oauth2_provider.W011toSILENCED_SYSTEM_CHECKSto prevent noisy repeated log warnings. - Documents why the warning is considered non-actionable for this codebase (manual migration dependencies already exist via
swappable_dependency).
File summaries
| File | Description |
|---|---|
awx/settings/defaults.py |
Silences oauth2_provider.W011 and adds rationale explaining why the warning is expected/benign in Ascender. |
Review details
- Files reviewed: 1/1 changed files
- Comments generated: 0
- Review effort level: Lite
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
|
#897 is the proper fix for this: it moves the refresh and ID token models into Your read of the situation is right, though: nothing is broken, the dependencies are declared by hand, and the check fires on a setup that is intentional here. They are mutually exclusive. Yours is one line and no risk; mine is two models, eight call sites and a migration that touches the token tables on upgrade. One thing worth knowing either way: once a model is swapped out Django skips operations on it, so DOT's later migrations never reach the old table. On existing installs #897 is verified on a fresh database and on a copy of a real one with 71 access tokens and a live refresh token: rows preserved, old tables dropped, both keys inside |
|
Closing this in favor of the full fix, even though its as painful as I thought it would be. |
After the upgrade, this is displayed over and over in the logs.
What changed.
PR #822, merged today, moved django-oauth-toolkit from 3.3.0 to 3.4.1. Release 3.4.1 (2026-08-21) added a brand-new system check, W011, that warns when the swapped AccessToken and RefreshToken models live in different Django apps. Our configuration has done exactly that since the initial import: the access token is swapped to a custom model in the main app, while the refresh token and ID token stay in the toolkit's own app, at defaults.py:526-529. So the configuration is old and unchanged. Only the check is new.
Why it repeats.
Every awx-manage command runs system checks at startup. The container launches around eight of them under supervisord, plus migrate and collectstatic, so the same warning is printed once per process.
Is anything actually broken?
No. The toolkit's own docstring for the check says the real hazard is Django being unable to order the initial migration for a cross-app circular foreign key. Our migration graph has already solved that by hand: the main-app migrations declare swappable dependencies on the refresh and ID token models, most recently in 0213_oauth2accesstoken_resource_and_more.py:14-15. The check runs awx-manage check clean with exit code 0, migrations apply, and the OAuth tests in PR #822 pass. The check's own comment says the warning exists because the setup is "almost always a mistake rather than an intention." Here it is intentional and long-established.