Skip to content

refactor(auth): align with scope-only token resources (campus #657) - #45

Merged
ngjunsiang merged 1 commit into
mainfrom
refactor/scope-only-token-resources
Sep 30, 2026
Merged

ngjunsiang merged 1 commit into
mainfrom
refactor/scope-only-token-resources

Conversation

@nycomp

@nycomp nycomp commented Sep 30, 2026

Copy link
Copy Markdown
Contributor

Summary

Compliance alignment with campus nyjc-computing/campus#657 (merged to weekly, head bdac1f8c), which closes the emission side of the #648 deprecation window:

  • OAuthToken.to_resource() now emits scope only — the scopes list key is gone from token resources
  • expiry_seconds is deprecated on OAuthToken: DeprecationWarning at both intake points (constructor InitVar, from_resource payload key)
  • POST /credentials now prefers expires_in; deprecated expiry_seconds still accepted with a warning; neither → 422

What was needed on our side — assessment

Live code paths were already compliant; nothing was broken on the wire:

Client path Status after #657
User.update() → PATCH token.to_resource() OK — payload is now scope-only, which the server's from_resource validation (#656) accepts
auth.token() / _exchange_code_for_token() / UserCredentials.from_resource OK — from_resource still accepts both scope and legacy scopes
expiry_seconds usage None — the client never passes it to OAuthToken, so no DeprecationWarning surfaces (verified: zero call sites)
logins.update(expiry_seconds), sessions.new() scopes list Unaffected — #657 explicitly keeps Login/AuthSession/DeviceCode models on their own expiry_seconds

What this PR changes (alignment + future-proofing):

  • campus-suite → weekly head bdac1f8c
  • Contract tests re-pinned to the scope-only emission: the PATCH validation-mirror test now asserts scope present / scopes absent (it failed against the bumped dep before this), and the GET nested-token fixture matches the current wire shape
  • Credentials.Provider.User.new() stub param renamed expiry_seconds → expires_in, per #657's explicit invitation ("campus-api-python can switch its POST to expires_in in its next PR") and the new POST route signature (scopes, expires_in; expiry_seconds deprecated)

Verification

Probed against campus-suite @ bdac1f8c:

  • to_resource() keys: created_at, expires_at, expires_in, id, refresh_token, refresh_token_expires_at, scope, token_type — no scopes ✅
  • from_resource accepts legacy scopes-list records and scope-only payloads ✅
  • OAuthToken(expiry_seconds=...) and from_resource({"expiry_seconds": ...}) each raise exactly one DeprecationWarning; expires_in is warning-free ✅

80 tests pass (1 was failing against the bumped dep before the re-pin); CI 3.11 + 3.12 green.

Looking ahead

Remaining #648 checklist items on the campus side: storage flip scopes → scope (item 3), then removal of the expiry_seconds alias and legacy read-time derivation (items 2+5). The client needs no further changes for the storage flip; when the alias removal lands, the renamed stub is already on the final contract.

campus #657 (merged to weekly, bdac1f8c) stops dual-emitting `scopes`
from token resources (#648 checklist item 4) and deprecates
OAuthToken's expiry_seconds with DeprecationWarning at both intake
points (constructor InitVar and from_resource payload key).

The client's live paths were already compliant: User.update() sends
to_resource() output, which the server validates via from_resource
(#656) and which now carries `scope` only; all deserialization goes
through from_resource, which still accepts both scope forms; and no
client code passes expiry_seconds to OAuthToken.

Changes:
- campus-suite bumped to weekly head bdac1f8c
- contract tests re-pinned to the scope-only emission (PATCH body and
  GET nested-token fixture)
- Credentials.Provider.User.new() stub param renamed
  expiry_seconds -> expires_in, matching the POST /credentials
  contract (expires_in preferred; expiry_seconds deprecated, still
  accepted with a warning; neither -> 422)

Refs nyjc-computing/campus#648, nyjc-computing/campus#657
@ngjunsiang
ngjunsiang merged commit 6a9c68a into main Sep 30, 2026
2 checks passed
@nycomp
nycomp deleted the refactor/scope-only-token-resources branch September 30, 2026 08:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants