Skip to content

fix(auth): token() targets /auth/v1/oauth/token, not the auth-code endpoint - #61

Merged
nycomp merged 1 commit into
mainfrom
fix/token-endpoint-path
Oct 2, 2026
Merged

nycomp merged 1 commit into
mainfrom
fix/token-endpoint-path

Conversation

@nycomp

@nycomp nycomp commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

Fixes #60

What

AuthRoot.token() built its URL as url_prefix + "/token" → /auth/v1/token, which is the provider's authorization-code session endpoint (campus/auth/provider.py): it requires code + redirect_uri and rejects every other grant type. So the client_credentials and refresh_token cases of token() could never succeed — with_app_session() died with 422 VALIDATION_FAILED (missing code/redirect_uri), verified against a current campus auth service (#60).

This points token() at the RFC 6749 token endpoint /auth/v1/oauth/token (campus/auth/routes/oauth.py — device_code / refresh_token / client_credentials), the same endpoint oauth.poll_for_token already uses, and pins both grant paths with contract tests.

Verification

  • Repo suite: 109 passed (107 existing + 2 new path pins).
  • Full chain verified locally against the campus client_credentials implementation (campus PR #731): fixed client → with_app_session() → grant → bearer on campus.api → /root/authenticate app-token resolution → assignments read reaching the resource lookup (409 not-found, not 401). Needed CAMPUS_AUTH_URL/CAMPUS_API_URL set for the campus test transport — a campus-side fixture gap, noted below.

Related

  • campus#731 (server: client_credentials grant on /auth/v1/oauth/token)
  • campus#334, campus-classroom#24 (the feature this unblocks)
  • campus-api-python#52 already deprecated HOSTNAME-derived base URLs; campus's test fixtures still rely on them (tests/fixtures/services.py sets HOSTNAME=campus.test but not CAMPUS_AUTH_URL/CAMPUS_API_URL), so a full-Client e2e in campus's suite needs those two env vars — left for a campus-side follow-up.

…dpoint

AuthRoot.token() built its request URL as url_prefix + "/token", which
resolves to /auth/v1/token — the provider's authorization-code session
endpoint (campus/auth/provider.py). That route requires code and
redirect_uri and rejects every grant_type but authorization_code, so the
client_credentials and refresh_token cases of token() could never
succeed: with_app_session() died with 422 VALIDATION_FAILED (missing
code/redirect_uri), verified against a current campus auth service.

The RFC 6749 token endpoint serving device_code, refresh_token, and
client_credentials grants lives at /auth/v1/oauth/token
(campus/auth/routes/oauth.py) — the same endpoint oauth.poll_for_token
already uses. Point token() there and pin both grant paths with
contract tests.

Fixes #60. Unblocks the client side of campus#334 /
campus-classroom#24 (server side: campus PR #731).
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

AuthRoot.token() posts to /auth/v1/token (auth-code endpoint), not /auth/v1/oauth/token — with_app_session() can never succeed

2 participants