Skip to content

feat: client update setters and get display for scope/bridge fields - #25

Merged
nycomp merged 2 commits into
mainfrom
feat/client-scope-bridge-setters
Oct 2, 2026
Merged

nycomp merged 2 commits into
mainfrom
feat/client-scope-bridge-setters

Conversation

@nycomp

@nycomp nycomp commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

What

Implements the surface sketched in #24:

  • campus client update gains:
    • --allowed-scope <scope> (repeatable) and --clear-allowed-scopes (mutually exclusive)
    • --upstream-scope <provider>=<scope> (repeatable; values grouped per provider, first-seen provider order)
    • --token-bridge / --no-token-bridge
  • campus client get / update / new output (table and --json) now carries allowed_scopes, upstream_scopes and token_bridge via _format_client.

Semantics (worth review)

The server's PATCH /clients/{id} full-replaces every provided field, so the list-valued flags REPLACE the whole stored value — help text and docstring say to re-pass everything the client must keep (same contract as --redirect-uri). Omitted fields are left untouched. Consequences:

  • The additive upstream_scopes patch on the #730 pre-impl checklist (Auth refactor: per-integration upstream OAuth clients — master delivery tracker campus#733) is one deliberate command re-passing both keys, e.g.
    campus client update -i uid-client-ef56f01c --upstream-scope google=... --upstream-scope google.classroom=...
  • --clear-allowed-scopes sends an explicit allowed_scopes=[] (fail-closed A1: an empty allowlist grants nothing).
  • Malformed provider=scope values and the clear+set combination are rejected client-side; the server remains authoritative for the rest (e.g. public clients can't hold token_bridge).

Dependencies

Tests

  • unit: _format_client carries/defaults the three fields (fields can't be dropped from --json again, cf. client list/get output omits redirect_uris and is_public #21).
  • integration: forwarding of all three flag groups, provider grouping/order, empty-list clear, tri-state token_bridge, the three client-side rejections, dry-run preview, JSON output.
  • 126 passed locally; ruff clean.

Closes #24

campus client update gains --allowed-scope (repeatable),
--clear-allowed-scopes, --upstream-scope provider=scope (repeatable,
grouped per provider) and --token-bridge/--no-token-bridge; client
get/update output and JSON now carry allowed_scopes, upstream_scopes
and token_bridge. List-valued flags REPLACE the stored value wholesale
(PATCH full-replace semantics), so the help text says to re-pass
everything the client must keep — which is also what makes the
additive two-key upstream_scopes patch on the #730 tracker one
deliberate command.

Also bumps the campus-suite pin to weekly 08d901c so the Client model
carries the three fields.

Requires the campus-api-python update() params (PR #65); the
campus-api-python lock bump follows once that merges.

Closes #24
Follows nyjc-computing/campus-api-python#65 — the SDK now accepts the
allowed_scopes/upstream_scopes/token_bridge kwargs the flags send.
@nycomp
nycomp merged commit ac7c07c into main Oct 2, 2026
1 check passed
@nycomp
nycomp deleted the feat/client-scope-bridge-setters branch October 2, 2026 12:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Admin tooling: CLI setters for Client.allowed_scopes / upstream_scopes / token_bridge

2 participants