Repository navigation
feat(auth): client update() accepts allowed_scopes/upstream_scopes/token_bridge - #65
Merged
Merged
Conversation
…ken_bridge
Clients.Client.update() forwards the three admin fields the auth
server's PATCH /clients/{id} has supported since the #705 series.
None = leave untouched, so PATCH bodies only carry what the caller
passed; list/dict values replace wholesale per server semantics.
Also bumps the campus-suite pin to weekly 08d901c (Client model now
declares the three fields) and updates the client resource-shape
fixture that test_model_field_types pins to to_resource().
Closes #64
nycomp
pushed a commit
to nyjc-computing/campus-cli
that referenced
this pull request
Oct 2, 2026
Follows nyjc-computing/campus-api-python#65 — the SDK now accepts the allowed_scopes/upstream_scopes/token_bridge kwargs the flags send.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
Extends
Clients.Client.update()with the three admin fields thatPATCH /clients/{id}has supported since the campus #705 series:allowed_scopes: list[str] | None— fail-closed token-scope allowlist (invariant A1)upstream_scopes: dict[str, list[str]] | None— per-provider upstream scope map (invariant B3)token_bridge: bool | None— broker token-bridge access (invariant C1; the server rejects it for public clients)Nonemeans leave untouched, so PATCH bodies carry only what the caller passed (existingtest_update_omits_unset_fieldscontract preserved, extended to the new fields). An explicit emptyallowed_scopesis sent — clearing the allowlist is a real fail-closed operation.Why
campus-cli is adding
campus client updatesetters /client getdisplay for these fields (nyjc-computing/campus-cli#24, admin tooling lane of the per-integration OAuth tracker nyjc-computing/campus#733). The CLI calls the SDK, so the params must land here first.Notes
08d901c—campus.model.Clientnow declares the three fields, and the client resource-shape fixture intest_model_field_types.pyis updated to the currentto_resource()shape (the old fixture predated the #705 fields, so the round-trip test failed against the bumped pin).Closes #64