Skip to content

fix(auth): token() passes a relative path — absolute URL was double-prefixed and 404ed live - #63

Merged
nycomp merged 1 commit into
mainfrom
fix/token-url-double-prefix
Oct 2, 2026
Merged

nycomp merged 1 commit into
mainfrom
fix/token-url-double-prefix

Conversation

@nycomp

@nycomp nycomp commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

Fixes #62

What

AuthRoot.token() built an absolute URL (base_url + url_prefix + "/oauth/token") and passed it to client.post() — but CampusRequest._build_url() always prepends the client's base_url (it expects a relative path, like every other resource method). Every token() call hit https://host/https://host/auth/v1/oauth/token → 404, verified live: curl to the identical endpoint returns 200 while the client returns NotFoundError.

This predates #61 (its "/token" construction had the same shape) and is the actual root cause of the long-standing "with_app_session 404s" in campus-classroom#24. It survived all in-repo tests because campus's Flask test transport routes absolute URLs leniently.

The fix passes a relative path — the same call shape as oauth.poll_for_token's "/oauth/token".

Tests

Verified live (dev deployment, 2026-10-02)

With this fix shadowed into campus-classroom's venv: auth.token(grant_type="client_credentials") → 200 (Bearer, scope campus.profile), and with_app_session() → campus.api assignments read reaches the resource lookup (409 not-found for a bogus id — authn passed).

…refixed

token() built an absolute URL (base_url + url_prefix + "/oauth/token")
and passed it to client.post(), but CampusRequest._build_url() always
prepends the client's base_url (it expects a relative path, like every
other resource method). Every token() call therefore hit
https://host/https://host/auth/v1/oauth/token and 404ed against real
deployments — verified live: curl to the same endpoint returns 200
while the client returns NotFoundError.

This predates #61 (the original "/token" construction had the same
shape) and is the actual root cause of the long-standing
"with_app_session 404s" in campus-classroom#24. It survived all
in-repo tests because campus's Flask test transport routes absolute
URLs leniently.

Pass a relative path (matching oauth.poll_for_token's "/oauth/token")
and pin it: the path tests now use a deliberately non-empty mock
base_url, and a regression test asserts the path stays relative (#62).

Verified live against the dev deployment with this fix: grant 200
(scope campus.profile), and with_app_session() read reaches the
campus.api resource lookup.
@nycomp
nycomp merged commit 72fbce7 into main Oct 2, 2026
2 checks passed
@nycomp
nycomp deleted the fix/token-url-double-prefix branch October 2, 2026 07:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

AuthRoot.token() passes an absolute URL to client.post() — CampusRequest double-prefixes it, so every token() call 404s against real deployments

2 participants