Skip to content

feat(auth): model the connections resource (list + disconnect, delegated user_id) - #81

Merged
ngjunsiang merged 1 commit into
feat/oauth-revokefrom
feat/auth-connections
Oct 4, 2026
Merged

ngjunsiang merged 1 commit into
feat/oauth-revokefrom
feat/auth-connections

Conversation

@nycomp

@nycomp nycomp commented Oct 4, 2026 •

Copy link
Copy Markdown
Contributor

Stack (merge in order): #78 -> #79 -> #80 -> #81 -> #82 -> #85
This is 4 of 6. Base is the branch of the PR below; each PR's diff shows only its own commit, and GitHub retargets it to main when the one below merges. Branches rebuilt on current main (9563443) — content unchanged from the original commits.
As always per SOP: after each merge, verify the issue auto-closed and close it manually if not.

Summary

  • New auth.connections resource covering the /auth/v1/connections/ surface (campus/auth/routes/connections.py, campus weekly @ 24adffc):
    • connections.list(user_id=None) → GET collection, returns the connections metadata list ({provider, integration, scopes, connected_at, expires_at} — token values never appear)
    • connections[provider].delete(user_id=None) → DELETE /connections/<provider>/
    • connections[provider][integration].delete(user_id=None) → DELETE /connections/<provider>/<integration>/ (e.g. google/classroom)
  • user_id is sent as a query parameter when given (the delegated basic-auth form; ignored by the server under a bearer token). 404 on disconnect surfaces as NotFoundError via raise_for_status, so callers can treat disconnect as idempotent — campus-profile already does.
  • Trailing slashes pinned on the DELETE routes (the auth app sets strict_slashes).

Replaces campus-profile's hand-built client.auth.client.get/delete(...) calls (integrations.py:64-158). Pairs with #56 (integrations registry).

Tests

tests/unit/test_connections.py — 6 contract tests pinning collection/list paths, delegated user_id query on all three routes, and the trailing slashes. Full suite: 152 passed.

Fixes #71

auth.connections.list(user_id=None) and auth.connections[provider]
[.integration].delete(user_id=None) cover GET/DELETE
/auth/v1/connections/...; campus-profile currently hand-builds these
paths over the raw client. Metadata-only surface (no token values);
404 on disconnect surfaces as NotFoundError so callers can treat it
as idempotent. user_id travels as a query param for delegated
(basic-auth) calls, matching the server's _resolve_target_user.

Fixes #71
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

feat(auth): model the connections resource (list + disconnect, delegated user_id)

2 participants