Repository navigation
refactor: revoke tokens via client library's oauth.revoke (api#80) - #29
Merged
Merged
Conversation
Logout's revoke_token raw-POSTed {auth_url}/oauth/revoke with a
form-encoded RFC 7009 payload because the client library had no
revocation surface. campus-api-python#80 models it (auth.oauth.revoke,
JSON body — the server accepts both on all OAuth endpoints); the CLI
now builds a device-mode auth root against the issuing endpoint
(AuthRoot + CampusRequest are public exports) and delegates.
The best-effort contract is unchanged: any APIError or transport
failure — or the library being unavailable at all — still reports
False so logout clears local credentials with only the
'revocation unavailable' note. The signature is unchanged too, so
logout_cmd and the integration tests that mock revoke_token are
untouched.
Also drops the now-unused revoke_url from get_auth_urls and rewrites
the four revoke unit tests against the library seam (plus a new
library-unavailable degradation test). Relocks campus-api-python
aece106 -> 0c0a36b (the previous pin predated even PR #70; the 0.3.0
version string is unchanged across api#78-#85).
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Retires the campus-cli workaround named in campus-api-python#73, now that api PRs #78–#85 are merged. Relock
aece106→0c0a36b(the previous pin predated even api#70; the0.3.0version string is unchanged across the whole range —resolved_referenceis the only signal).What changed
revoke_token()(campus_cli/auth/common.py) raw-requests-POSTed{auth_url}/oauth/revokewith a form-encoded RFC 7009 payload. It now builds a device-mode auth root against the issuing endpoint (AuthRoot+CampusRequestare publiccampus_pythonexports) and delegates toauth.oauth.revoke(token, client_id, token_type_hint)— preserving the endpoint-targeting rule that logout must revoke where the token was minted (auth_urlarg, still honored).Deliberately preserved:
APIErroror transport failure returnsFalseso logout still clears local credentials with only the "revocation unavailable" note; the library raises where the old shim returned False, sorevoke_tokenwraps it.logout_cmd(login.py:328-342) and the integration tests that mockcampus_cli.auth.login.revoke_tokenare untouched.ImportErrornow also returnsFalse, matchingget_api_client's clean degradation, with a new unit test.Also drops the now-unused
revoke_urlkey fromget_auth_urls()and rewrites the four revoke unit tests against the library seam (asserting the RFC 7009 args, device mode, and issuing-endpoint base_url).Wire-format note: the payload moves from form-encoded to JSON; the server's
unpack_oauth_requestaccepts both on all OAuth endpoints.Verification
ruff checkclean (pre-push hook passes).