Repository navigation
fix(auth): token() targets /auth/v1/oauth/token, not the auth-code endpoint - #61
Merged
Merged
Conversation
…dpoint AuthRoot.token() built its request URL as url_prefix + "/token", which resolves to /auth/v1/token — the provider's authorization-code session endpoint (campus/auth/provider.py). That route requires code and redirect_uri and rejects every grant_type but authorization_code, so the client_credentials and refresh_token cases of token() could never succeed: with_app_session() died with 422 VALIDATION_FAILED (missing code/redirect_uri), verified against a current campus auth service. The RFC 6749 token endpoint serving device_code, refresh_token, and client_credentials grants lives at /auth/v1/oauth/token (campus/auth/routes/oauth.py) — the same endpoint oauth.poll_for_token already uses. Point token() there and pin both grant paths with contract tests. Fixes #60. Unblocks the client side of campus#334 / campus-classroom#24 (server side: campus PR #731).
This was referenced Oct 2, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #60
What
AuthRoot.token()built its URL asurl_prefix + "/token"→/auth/v1/token, which is the provider's authorization-code session endpoint (campus/auth/provider.py): it requirescode+redirect_uriand rejects every other grant type. So theclient_credentialsandrefresh_tokencases oftoken()could never succeed —with_app_session()died with 422 VALIDATION_FAILED (missingcode/redirect_uri), verified against a current campus auth service (#60).This points
token()at the RFC 6749 token endpoint/auth/v1/oauth/token(campus/auth/routes/oauth.py— device_code / refresh_token / client_credentials), the same endpointoauth.poll_for_tokenalready uses, and pins both grant paths with contract tests.Verification
client_credentialsimplementation (campus PR #731): fixed client →with_app_session()→ grant → bearer on campus.api →/root/authenticateapp-token resolution → assignments read reaching the resource lookup (409 not-found, not 401). NeededCAMPUS_AUTH_URL/CAMPUS_API_URLset for the campus test transport — a campus-side fixture gap, noted below.Related
tests/fixtures/services.pysetsHOSTNAME=campus.testbut notCAMPUS_AUTH_URL/CAMPUS_API_URL), so a full-Client e2e in campus's suite needs those two env vars — left for a campus-side follow-up.