Skip to content

feat(auth): complete auth coverage — clients access.check, Clients.new scope fields, Credentials.User.new - #83

Merged
nycomp merged 1 commit into
mainfrom
feat/auth-coverage
Oct 4, 2026
Merged

nycomp merged 1 commit into
mainfrom
feat/auth-coverage

Conversation

@nycomp

@nycomp nycomp commented Oct 4, 2026

Copy link
Copy Markdown
Contributor

Summary

The three smaller auth-service gaps from the 2026-10-04 delta sweep (campus weekly):

  1. Clients.Client.access.check(vault, permission) — GET /auth/v1/clients/<id>/access/check?vault=&permission= (leaf path, no trailing slash, matching the route registration) → {"vault": ..., "permission": <bool>}. The only access sub-route the client lacked.
  2. Clients.new() now forwards allowed_scopes, upstream_scopes, token_bridge (omitted when not given), matching the POST /clients/ route; update() has supported them since PR feat(auth): client update() accepts allowed_scopes/upstream_scopes/token_bridge #65.
  3. Credentials.Provider.User.new(scopes, expires_in) — implements the stale NotImplementedError stub. POST /auth/v1/credentials/<provider>/<user_id> with {scopes, expires_in} (the server takes client_id from the request's auth context, not the body); parses the 201 flat resource into UserCredentials.

Tests

tests/unit/test_auth_coverage.py — 4 contract tests (query params + path for check; body omission/forwarding for new(); POST path/body + deserialization for credentials). Full suite: 150 passed.

Fixes #76

…fields, Credentials.User.new

- Clients.Client.access.check(vault, permission): GET the
  /access/check leaf route with vault/permission query params
- Clients.new(): forward allowed_scopes, upstream_scopes,
  token_bridge (update() has supported them since PR #65)
- Credentials.Provider.User.new(scopes, expires_in): implement the
  stale NotImplementedError stub — POST /credentials/<provider>/
  <user_id> sends {scopes, expires_in}; the client_id comes from the
  request's auth context, not the body

Fixes #76
@nycomp
nycomp merged commit 337e811 into main Oct 4, 2026
2 checks passed
@nycomp
nycomp deleted the feat/auth-coverage branch October 4, 2026 01:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

feat(auth): complete auth coverage — clients access.check, Clients.new scope fields, Credentials.User.new stub

2 participants