Skip to content

refactor: revoke tokens via client library's oauth.revoke (api#80) - #29

Merged
nycomp merged 1 commit into
mainfrom
refactor/revoke-via-client
Oct 4, 2026
Merged

nycomp merged 1 commit into
mainfrom
refactor/revoke-via-client

Conversation

@nycomp

@nycomp nycomp commented Oct 4, 2026

Copy link
Copy Markdown
Contributor

Retires the campus-cli workaround named in campus-api-python#73, now that api PRs #78–#85 are merged. Relock aece106 → 0c0a36b (the previous pin predated even api#70; the 0.3.0 version string is unchanged across the whole range — resolved_reference is the only signal).

What changed

revoke_token() (campus_cli/auth/common.py) raw-requests-POSTed {auth_url}/oauth/revoke with a form-encoded RFC 7009 payload. It now builds a device-mode auth root against the issuing endpoint (AuthRoot + CampusRequest are public campus_python exports) and delegates to auth.oauth.revoke(token, client_id, token_type_hint) — preserving the endpoint-targeting rule that logout must revoke where the token was minted (auth_url arg, still honored).

Deliberately preserved:

  • Best-effort bool contract — any APIError or transport failure returns False so logout still clears local credentials with only the "revocation unavailable" note; the library raises where the old shim returned False, so revoke_token wraps it.
  • Signature unchanged — logout_cmd (login.py:328-342) and the integration tests that mock campus_cli.auth.login.revoke_token are untouched.
  • Library-unavailable degradation — an ImportError now also returns False, matching get_api_client's clean degradation, with a new unit test.

Also drops the now-unused revoke_url key from get_auth_urls() and rewrites the four revoke unit tests against the library seam (asserting the RFC 7009 args, device mode, and issuing-endpoint base_url).

Wire-format note: the payload moves from form-encoded to JSON; the server's unpack_oauth_request accepts both on all OAuth endpoints.

Verification

  • Full suite green in the worktree venv against the new lock: 147 passed (was 146 tests' worth of coverage; the revoke block is now 5 tests incl. the new degradation case).
  • ruff check clean (pre-push hook passes).

Logout's revoke_token raw-POSTed {auth_url}/oauth/revoke with a
form-encoded RFC 7009 payload because the client library had no
revocation surface. campus-api-python#80 models it (auth.oauth.revoke,
JSON body — the server accepts both on all OAuth endpoints); the CLI
now builds a device-mode auth root against the issuing endpoint
(AuthRoot + CampusRequest are public exports) and delegates.

The best-effort contract is unchanged: any APIError or transport
failure — or the library being unavailable at all — still reports
False so logout clears local credentials with only the
'revocation unavailable' note. The signature is unchanged too, so
logout_cmd and the integration tests that mock revoke_token are
untouched.

Also drops the now-unused revoke_url from get_auth_urls and rewrites
the four revoke unit tests against the library seam (plus a new
library-unavailable degradation test). Relocks campus-api-python
aece106 -> 0c0a36b (the previous pin predated even PR #70; the 0.3.0
version string is unchanged across api#78-#85).
@nycomp
nycomp merged commit 4190b9f into main Oct 4, 2026
1 check passed
@nycomp
nycomp deleted the refactor/revoke-via-client branch October 4, 2026 04:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants