Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion campus_python/auth/v1/credentials.py
Original file line number Diff line number Diff line change
Expand Up @@ -80,7 +80,7 @@ def get(self) -> campus.model.UserCredentials:
def new(
self,
scopes: "list[str]",
expiry_seconds: int,
expires_in: int,
) -> campus.model.UserCredentials:
raise NotImplementedError(
"Method not expected to be called on API"
Expand Down
2 changes: 1 addition & 1 deletion poetry.lock

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

21 changes: 11 additions & 10 deletions tests/unit/test_oauth_token_contract.py
Original file line number Diff line number Diff line change
Expand Up @@ -9,11 +9,12 @@
- POST /auth/v1/token responses carry standard RFC keys (access_token,
token_type, expires_in, scope) which OAuthToken.from_resource maps to
campus names;
- GET /credentials/... resources nest the token with both `scope`
(string) and `scopes` (list) during the compat window;
- GET /credentials/... resources nest the token carrying the RFC 6749
`scope` string only (scope-only emission since campus #657);
from_resource still accepts legacy `scopes` lists;
- PATCH /credentials/... bodies are validated server-side via
OAuthToken.from_resource() (campus #656), which accepts the
dual-emitted `scope` string alias, legacy `expiry_seconds`, and bags
OAuthToken.from_resource() (campus #656), which maps the RFC 6749
`scope` string to `scopes`, accepts legacy `expiry_seconds`, and bags
unknown provider keys into provider_fields; User.update() sends the
full to_resource() output.
"""
Expand All @@ -38,7 +39,8 @@
}

# Exact credentials-resource shape emitted by campus weekly
# (UserCredentials.to_resource() with its nested OAuthToken token).
# (UserCredentials.to_resource() with its nested OAuthToken token;
# scope-only token emission since campus #657).
CREDENTIALS_RESOURCE = {
"id": "cred1",
"created_at": "2026-09-30T06:31:24.582763+00:00",
Expand All @@ -53,7 +55,6 @@
"token_type": "Bearer",
"refresh_token": "rt123",
"refresh_token_expires_at": None,
"scopes": ["campus.profile", "campus.identities"],
"scope": "campus.profile campus.identities",
},
}
Expand Down Expand Up @@ -138,16 +139,16 @@ def test_update_patches_credentials_endpoint(self):
def test_patch_body_passes_server_validation(self):
"""The sent token payload must pass OAuthToken.from_resource().

Mirrors the server-side validation (campus #656), which accepts
the RFC 6749 `scope` string alias dual-emitted by to_resource()
alongside `scopes` (campus #650).
Mirrors the server-side validation (campus #656). Token
resources emit `scope` only since campus #657 (deprecation
checklist item 4); from_resource maps it back to `scopes`.
"""
with patch.dict(os.environ, {"CLIENT_ID": "cid123"}):
self.auth.credentials["campus"]["user1"].update(self.token)
body = self.client.patch.call_args.kwargs["json"]
sent_token = body["token"]
self.assertIn("scope", sent_token)
self.assertIn("scopes", sent_token)
self.assertNotIn("scopes", sent_token)
validated = campus.model.OAuthToken.from_resource(sent_token)
self.assertEqual(validated.id, "tok123")
self.assertEqual(validated.scopes, ["campus.profile", "campus.identities"])
Expand Down
Loading