Skip to content

feat(client): --redirect-uri on update for in-place URI registration - #16

Merged
nycomp merged 3 commits into
mainfrom
feat/client-update-redirect-uri
Oct 1, 2026
Merged

nycomp merged 3 commits into
mainfrom
feat/client-update-redirect-uri

Conversation

@nycomp

@nycomp nycomp commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Closes #15

Summary

  • campus client update gains a repeatable --redirect-uri, mirroring client new: it forwards redirect_uris=[...] to Clients.update(), which the server's PATCH route replaces wholesale.
  • Validation accepts any of --name/--description/--redirect-uri (previously name/description only); the dry-run snippet includes redirect_uris only when passed.
  • Help text and docs/PRD.md state the replace-not-merge semantics — an admin adding one URI must re-pass the full list, since campus#651 will enforce exact-match redirect_uri at /authorize (RFC 6749 §3.1.2.2).
  • docs/PRD.md command inventory fully refreshed to match the shipped CLI: top-level campus client/campus vault prefixes (was the non-existent campus auth client/vault), adds client list and vault delete, client new --public/--redirect-uri, access-command --vault/--permission flags, accurate client revoke description, and a note on the feat: --dry-run flag showing equivalent Python API code #13 --dry-run flag.

This is the registration path campus#651 needs for existing clients (e.g. campus-classroom-dev): today the only option is re-creating the client, which rotates client_id/client_secret.

Dependency resolved

The blocker was campus-api-python#51 (PUT→PATCH 405 in Clients.update()), merged 2026-09-30 (fixes #50 upstream). The second commit here refreshes the lock pin d2fba82 → 7e0b450 to pick it up, so this PR is self-contained: merging it fixes client update at runtime, flag and all. (Verified locally: installed client sends PATCH, 80 tests + ruff green on the bumped lock.)

Tests

  • dry-run: redirect_uris appears only when passed (multi-value order preserved)
  • behavior (tests/integration/test_client_update.py): pass-through contract, no-field validation error, name+redirect combination
  • full suite: 80 passed; ruff clean

Mirrors the repeatable --redirect-uri from 'client new' so existing
clients can have redirect_uris replaced without recreating the client
(rotating client_id/secret) — the operational prerequisite for exact
redirect_uri matching at /authorize (campus#651, RFC 6749 §3.1.2.2).

Passes redirect_uris through to Clients.update(); validation accepts
any of --name/--description/--redirect-uri; the dry-run snippet shows
the kwarg only when passed. Help text and PRD state the replace-not-
merge semantics: re-pass the full list when adding a URI.

Runtime needs campus-api-python#51 (PUT->PATCH) plus a lock pin
refresh; tests mock the API layer and pass either way. Refs #15.
d2fba82 -> 7e0b450: picks up the PATCH verb fix for Clients.update()
(upstream #51), so 'campus client update --redirect-uri' works at
runtime the moment this merges. Kept on this branch rather than main
so the bump lands atomically with the feature that needs it.
The inventory predated PRs #9-#13: client/vault commands were shown
under the non-existent 'campus auth' prefix (real groups are top-level
'campus client' / 'campus vault'); 'client list' and 'vault delete'
were missing; 'client new' lacked --public/--redirect-uri; the access
commands lacked --vault/--permission; 'client revoke' was described as
revoking access when it rotates the client secret. Adds a note on the
#13 --dry-run flag.
@nycomp
nycomp merged commit 03541b5 into main Oct 1, 2026
1 check passed
@nycomp
nycomp deleted the feat/client-update-redirect-uri branch October 1, 2026 02:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

client update: add --redirect-uri so existing clients' redirect_uris can be updated in place

2 participants