Skip to content

feat(auth): OAuth token revocation — POST /auth/v1/oauth/revoke (RFC 7009) #73

Description

@nycomp

Description

The client can obtain tokens (device flow via auth.oauth, client_credentials/refresh_token via auth.token()) but cannot revoke them. campus-cli still raw-calls the revoke endpoint (campus_cli/auth/common.py builds /oauth/revoke); the rest of its device flow moved in-library with #70.

Server surface (campus weekly, campus/auth/routes/oauth.py)

  • POST /auth/v1/oauth/revoke — body: token (required), client_id (required), token_type_hint (optional)
  • Returns 200 {} per RFC 7009 regardless of whether the token was active

Suggested client shape

auth.oauth.revoke(token, client_id, token_type_hint=None) on the existing OAuth resource (paths under /auth/v1/oauth/... since PR #70).

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions