Repository navigation
feat(client): --redirect-uri on update for in-place URI registration - #16
Merged
Merged
Conversation
Mirrors the repeatable --redirect-uri from 'client new' so existing clients can have redirect_uris replaced without recreating the client (rotating client_id/secret) — the operational prerequisite for exact redirect_uri matching at /authorize (campus#651, RFC 6749 §3.1.2.2). Passes redirect_uris through to Clients.update(); validation accepts any of --name/--description/--redirect-uri; the dry-run snippet shows the kwarg only when passed. Help text and PRD state the replace-not- merge semantics: re-pass the full list when adding a URI. Runtime needs campus-api-python#51 (PUT->PATCH) plus a lock pin refresh; tests mock the API layer and pass either way. Refs #15.
d2fba82 -> 7e0b450: picks up the PATCH verb fix for Clients.update() (upstream #51), so 'campus client update --redirect-uri' works at runtime the moment this merges. Kept on this branch rather than main so the bump lands atomically with the feature that needs it.
The inventory predated PRs #9-#13: client/vault commands were shown under the non-existent 'campus auth' prefix (real groups are top-level 'campus client' / 'campus vault'); 'client list' and 'vault delete' were missing; 'client new' lacked --public/--redirect-uri; the access commands lacked --vault/--permission; 'client revoke' was described as revoking access when it rotates the client secret. Adds a note on the #13 --dry-run flag.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #15
Summary
campus client updategains a repeatable--redirect-uri, mirroringclient new: it forwardsredirect_uris=[...]toClients.update(), which the server's PATCH route replaces wholesale.--name/--description/--redirect-uri(previously name/description only); the dry-run snippet includesredirect_urisonly when passed.docs/PRD.mdstate the replace-not-merge semantics — an admin adding one URI must re-pass the full list, since campus#651 will enforce exact-matchredirect_uriat/authorize(RFC 6749 §3.1.2.2).docs/PRD.mdcommand inventory fully refreshed to match the shipped CLI: top-levelcampus client/campus vaultprefixes (was the non-existentcampus auth client/vault), addsclient listandvault delete,client new--public/--redirect-uri, access-command--vault/--permissionflags, accurateclient revokedescription, and a note on the feat: --dry-run flag showing equivalent Python API code #13--dry-runflag.This is the registration path campus#651 needs for existing clients (e.g.
campus-classroom-dev): today the only option is re-creating the client, which rotatesclient_id/client_secret.Dependency resolved
The blocker was campus-api-python#51 (PUT→PATCH 405 in
Clients.update()), merged 2026-09-30 (fixes #50 upstream). The second commit here refreshes the lock pind2fba82 → 7e0b450to pick it up, so this PR is self-contained: merging it fixesclient updateat runtime, flag and all. (Verified locally: installed client sends PATCH, 80 tests + ruff green on the bumped lock.)Tests
redirect_urisappears only when passed (multi-value order preserved)tests/integration/test_client_update.py): pass-through contract, no-field validation error, name+redirect combination