Skip to content

feat(auth): client update() accepts allowed_scopes/upstream_scopes/token_bridge - #65

Merged
nycomp merged 1 commit into
mainfrom
feat/client-scope-bridge-setters
Oct 2, 2026
Merged

nycomp merged 1 commit into
mainfrom
feat/client-scope-bridge-setters

Conversation

@nycomp

@nycomp nycomp commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

What

Extends Clients.Client.update() with the three admin fields that PATCH /clients/{id} has supported since the campus #705 series:

  • allowed_scopes: list[str] | None — fail-closed token-scope allowlist (invariant A1)
  • upstream_scopes: dict[str, list[str]] | None — per-provider upstream scope map (invariant B3)
  • token_bridge: bool | None — broker token-bridge access (invariant C1; the server rejects it for public clients)

None means leave untouched, so PATCH bodies carry only what the caller passed (existing test_update_omits_unset_fields contract preserved, extended to the new fields). An explicit empty allowed_scopes is sent — clearing the allowlist is a real fail-closed operation.

Why

campus-cli is adding campus client update setters / client get display for these fields (nyjc-computing/campus-cli#24, admin tooling lane of the per-integration OAuth tracker nyjc-computing/campus#733). The CLI calls the SDK, so the params must land here first.

Notes

  • Also bumps the campus-suite pin to weekly 08d901c — campus.model.Client now declares the three fields, and the client resource-shape fixture in test_model_field_types.py is updated to the current to_resource() shape (the old fixture predated the #705 fields, so the round-trip test failed against the bumped pin).
  • No server change required; campus/auth routes already accept and return all three fields.

Closes #64

…ken_bridge

Clients.Client.update() forwards the three admin fields the auth
server's PATCH /clients/{id} has supported since the #705 series.
None = leave untouched, so PATCH bodies only carry what the caller
passed; list/dict values replace wholesale per server semantics.

Also bumps the campus-suite pin to weekly 08d901c (Client model now
declares the three fields) and updates the client resource-shape
fixture that test_model_field_types pins to to_resource().

Closes #64
@nycomp
nycomp merged commit aece106 into main Oct 2, 2026
2 checks passed
@nycomp
nycomp deleted the feat/client-scope-bridge-setters branch October 2, 2026 12:12
nycomp pushed a commit to nyjc-computing/campus-cli that referenced this pull request Oct 2, 2026
Follows nyjc-computing/campus-api-python#65 — the SDK now accepts the
allowed_scopes/upstream_scopes/token_bridge kwargs the flags send.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

SDK: client update() params for allowed_scopes / upstream_scopes / token_bridge

2 participants