Repository navigation
refactor(auth): send full token resource in credentials PATCH - #44
Merged
Merged
Conversation
campus #656 (merged to weekly, 2e46783c) validates PATCH /credentials token bodies via OAuthToken.from_resource(), which accepts the RFC 6749 `scope` string alias that to_resource() dual-emits, maps legacy expiry_seconds, and bags unknown provider keys into provider_fields. The scope-alias strip added for #40 is no longer necessary; User.update() sends the full to_resource() output again. Also bumps campus-suite to weekly head 2e46783c carrying the fix, and updates the contract tests to pin the new validation contract, including the post-deprecation scope-only shape. Refs nyjc-computing/campus#655
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Retires the
scope-alias workaround added in #43, now that campus fixed the PATCH validation gap in nyjc-computing/campus#655 via nyjc-computing/campus#656 (merged toweekly, head2e46783c).User.update()again sends the fullOAuthToken.to_resource()output — including the RFC 6749scopestring that #650 dual-emits alongsidescopes. Campus validates PATCH bodies viaOAuthToken.from_resource()now, which:scope→scopes(so the post-deprecation scope-only shape is already accepted),expiry_seconds→expires_in,provider_fieldsinstead of rejecting them,ValueErroron genuinely invalid tokens → 422 (preserving the #325 contract).Verification
Probed against campus-suite @ weekly head
2e46783c:OAuthToken.from_resource(full to_resource())— ✅ round-trips (id, token_type, expires_in, scopes, scope all preserved){"access_token", "expires_in", "scope"}— ✅ accepted (post-deprecation shape)id_token) — ✅ bagged intoprovider_fields{"access_token"}with no expiry — ✅ still rejected (ValueError)Changes
credentials.py: removed thetoken_payload.pop("scope", None)strip (net −4 lines; back to the pre-fix(auth): keep PATCH credentials body within server-accepted token keys #43 payload shape)poetry.lock: campus-suite →2e46783ctests/unit/test_oauth_token_contract.py: validation-mirror test now usesfrom_resource(assertsscopeis sent), plus a new test pinning the post-deprecation scope-only shapeCompatibility note
The client's model surface comes from campus-suite pinned to
weekly, so running this client against a campus deployment older than #656 is already outside its support envelope; dropping the shim keeps the client aligned with the dev API truth instead of carrying a permanent compat shim. (The stripped payload would also still be accepted by #656 servers, so this direction is the only breaking one, and only for stale deployments.)Test plan
80 passed (79 prior + 1 new), Python 3.11.4 venv with campus-suite @
2e46783c.