Repository navigation
refactor(auth): align with scope-only token resources (campus #657) - #45
Merged
Merged
Conversation
campus #657 (merged to weekly, bdac1f8c) stops dual-emitting `scopes` from token resources (#648 checklist item 4) and deprecates OAuthToken's expiry_seconds with DeprecationWarning at both intake points (constructor InitVar and from_resource payload key). The client's live paths were already compliant: User.update() sends to_resource() output, which the server validates via from_resource (#656) and which now carries `scope` only; all deserialization goes through from_resource, which still accepts both scope forms; and no client code passes expiry_seconds to OAuthToken. Changes: - campus-suite bumped to weekly head bdac1f8c - contract tests re-pinned to the scope-only emission (PATCH body and GET nested-token fixture) - Credentials.Provider.User.new() stub param renamed expiry_seconds -> expires_in, matching the POST /credentials contract (expires_in preferred; expiry_seconds deprecated, still accepted with a warning; neither -> 422) Refs nyjc-computing/campus#648, nyjc-computing/campus#657
This was referenced Sep 30, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Compliance alignment with campus nyjc-computing/campus#657 (merged to
weekly, headbdac1f8c), which closes the emission side of the #648 deprecation window:OAuthToken.to_resource()now emitsscopeonly — thescopeslist key is gone from token resourcesexpiry_secondsis deprecated on OAuthToken:DeprecationWarningat both intake points (constructor InitVar,from_resourcepayload key)/credentialsnow prefersexpires_in; deprecatedexpiry_secondsstill accepted with a warning; neither → 422What was needed on our side — assessment
Live code paths were already compliant; nothing was broken on the wire:
User.update()→ PATCHtoken.to_resource()from_resourcevalidation (#656) acceptsauth.token()/_exchange_code_for_token()/UserCredentials.from_resourcefrom_resourcestill accepts bothscopeand legacyscopesexpiry_secondsusageOAuthToken, so noDeprecationWarningsurfaces (verified: zero call sites)logins.update(expiry_seconds),sessions.new()scopes listLogin/AuthSession/DeviceCodemodels on their ownexpiry_secondsWhat this PR changes (alignment + future-proofing):
bdac1f8cscopepresent /scopesabsent (it failed against the bumped dep before this), and the GET nested-token fixture matches the current wire shapeCredentials.Provider.User.new()stub param renamedexpiry_seconds→expires_in, per #657's explicit invitation ("campus-api-python can switch its POST to expires_in in its next PR") and the new POST route signature (scopes,expires_in;expiry_secondsdeprecated)Verification
Probed against campus-suite @
bdac1f8c:to_resource()keys:created_at, expires_at, expires_in, id, refresh_token, refresh_token_expires_at, scope, token_type— noscopes✅from_resourceaccepts legacyscopes-list records and scope-only payloads ✅OAuthToken(expiry_seconds=...)andfrom_resource({"expiry_seconds": ...})each raise exactly oneDeprecationWarning;expires_inis warning-free ✅80 tests pass (1 was failing against the bumped dep before the re-pin); CI 3.11 + 3.12 green.
Looking ahead
Remaining #648 checklist items on the campus side: storage flip
scopes→scope(item 3), then removal of theexpiry_secondsalias and legacy read-time derivation (items 2+5). The client needs no further changes for the storage flip; when the alias removal lands, the renamed stub is already on the final contract.