Skip to content

feat(api): add explicit oauth protocol bindings - #34

Draft
bdsqqq wants to merge 1 commit into
feat/api-parity-webhooksfrom
feat/api-parity-oauth
Draft

bdsqqq wants to merge 1 commit into
feat/api-parity-webhooksfrom
feat/api-parity-oauth

Conversation

@bdsqqq

@bdsqqq bdsqqq commented Sep 23, 2026 •

Copy link
Copy Markdown
Owner

changes

  • local OAuth URL/PKCE plus explicit exchange, refresh, client-credentials and revocation
  • canonical documented forms, fixed endpoints, no redirects/retries or implicit persistence
  • separate secret-output consent for tokens and plain-PKCE URLs

evidence

exact-head d330986 CI 35933888156 passes all jobs, including existing sandbox scenarios (NOT live OAuth grants). full offline checks, final 33 focused tests, independent full-router consent probes and compiled PKCE smoke pass. macos smoke uses ad-hoc signing, not release notarization.
review found plain-PKCE verifier output lacked consent; fixed and re-reviewed.

limits

no live grants issued/refreshed/revoked; authorized OAuth app and disposable credentials required. scope changes can revoke existing app tokens. not automatic login/callback validation or full parity. stacked on #33; draft only.

Session-Id: 01a0c9ff-ccff-7106-aa80-086d00182476
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant