Skip to content

refactor(auth): send full token resource in credentials PATCH - #44

Merged
ngjunsiang merged 1 commit into
mainfrom
refactor/retire-scope-alias-workaround
Sep 30, 2026
Merged

ngjunsiang merged 1 commit into
mainfrom
refactor/retire-scope-alias-workaround

Conversation

@nycomp

@nycomp nycomp commented Sep 30, 2026

Copy link
Copy Markdown
Contributor

Summary

Retires the scope-alias workaround added in #43, now that campus fixed the PATCH validation gap in nyjc-computing/campus#655 via nyjc-computing/campus#656 (merged to weekly, head 2e46783c).

User.update() again sends the full OAuthToken.to_resource() output — including the RFC 6749 scope string that #650 dual-emits alongside scopes. Campus validates PATCH bodies via OAuthToken.from_resource() now, which:

  • maps scope → scopes (so the post-deprecation scope-only shape is already accepted),
  • maps legacy expiry_seconds → expires_in,
  • bags unknown provider keys into provider_fields instead of rejecting them,
  • still raises ValueError on genuinely invalid tokens → 422 (preserving the #325 contract).

Verification

Probed against campus-suite @ weekly head 2e46783c:

  • OAuthToken.from_resource(full to_resource()) — ✅ round-trips (id, token_type, expires_in, scopes, scope all preserved)
  • scope-only payload {"access_token", "expires_in", "scope"} — ✅ accepted (post-deprecation shape)
  • unknown key (id_token) — ✅ bagged into provider_fields
  • {"access_token"} with no expiry — ✅ still rejected (ValueError)

Changes

  • credentials.py: removed the token_payload.pop("scope", None) strip (net −4 lines; back to the pre-fix(auth): keep PATCH credentials body within server-accepted token keys #43 payload shape)
  • poetry.lock: campus-suite → 2e46783c
  • tests/unit/test_oauth_token_contract.py: validation-mirror test now uses from_resource (asserts scope is sent), plus a new test pinning the post-deprecation scope-only shape

Compatibility note

The client's model surface comes from campus-suite pinned to weekly, so running this client against a campus deployment older than #656 is already outside its support envelope; dropping the shim keeps the client aligned with the dev API truth instead of carrying a permanent compat shim. (The stripped payload would also still be accepted by #656 servers, so this direction is the only breaking one, and only for stale deployments.)

Test plan

80 passed (79 prior + 1 new), Python 3.11.4 venv with campus-suite @ 2e46783c.

campus #656 (merged to weekly, 2e46783c) validates PATCH /credentials
token bodies via OAuthToken.from_resource(), which accepts the RFC 6749
`scope` string alias that to_resource() dual-emits, maps legacy
expiry_seconds, and bags unknown provider keys into provider_fields.
The scope-alias strip added for #40 is no longer necessary;
User.update() sends the full to_resource() output again.

Also bumps campus-suite to weekly head 2e46783c carrying the fix, and
updates the contract tests to pin the new validation contract,
including the post-deprecation scope-only shape.

Refs nyjc-computing/campus#655
@ngjunsiang
ngjunsiang merged commit 5776147 into main Sep 30, 2026
2 checks passed
@nycomp
nycomp deleted the refactor/retire-scope-alias-workaround branch September 30, 2026 07:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants