Skip to content

feat(auth): OAuth token revocation — POST /auth/v1/oauth/revoke (RFC 7009) - #80

Merged
ngjunsiang merged 1 commit into
feat/request-guardsfrom
feat/oauth-revoke
Oct 4, 2026
Merged

ngjunsiang merged 1 commit into
feat/request-guardsfrom
feat/oauth-revoke

Conversation

@nycomp

@nycomp nycomp commented Oct 4, 2026 •

Copy link
Copy Markdown
Contributor

Stack (merge in order): #78 -> #79 -> #80 -> #81 -> #82 -> #85
This is 3 of 6. Base is the branch of the PR below; each PR's diff shows only its own commit, and GitHub retargets it to main when the one below merges. Branches rebuilt on current main (9563443) — content unchanged from the original commits.
As always per SOP: after each merge, verify the issue auto-closed and close it manually if not.

Summary

  • Adds auth.oauth.revoke(token, client_id, token_type_hint=None) to the existing OAuth resource (paths under /auth/v1/oauth/... since the PR fix: bug sweep — timetable envelopes, session cleanup, oauth device flow #70 fix sweep).
  • Pins the wire contract from campus weekly (campus/auth/routes/oauth.py): leaf path /oauth/revoke, body {token, client_id} plus optional token_type_hint (only sent when given).
  • Per RFC 7009 §2.2 the server returns 200 {} whether or not the token was active — errors (missing token → 400 invalid_request, unknown client_id → 400 invalid_client) surface as APIError subclasses through raise_for_status(). The docstring warns callers not to read token validity from the response.

Unblocks campus-cli, which currently raw-calls this endpoint (campus_cli/auth/common.py).

Tests

tests/unit/test_oauth_revoke.py — 2 contract tests pinning the POST path and the body with/without the hint. Full suite: 148 passed.

Fixes #73

auth.oauth.revoke(token, client_id, token_type_hint=None) POSTs
/auth/v1/oauth/revoke, the endpoint campus-cli still raw-calls.
The server returns 200 {} regardless of token state (RFC 7009 §2.2);
errors (missing token, invalid client) surface as APIError subclasses
via raise_for_status.

Fixes #73
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

feat(auth): OAuth token revocation — POST /auth/v1/oauth/revoke (RFC 7009)

2 participants