Normalize Slack-shaped OAuth token exchange payloads - #1346
Conversation
Slack's oauth.v2.access nests user tokens under authed_user (top-level
access_token is the bot token, absent entirely for user-scope-only
apps) and reports failures as { ok: false, error } with HTTP 200. The
exchange handler now hoists the nested token fields to the standard
top-level names (never overwriting present ones) and maps ok:false
payloads to the standard exchange-failure response, so a platform
Slack app configured with user_scope via extraAuthorizeParams works
end to end without provider-specific code downstream.
Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>
|
No actionable comments were generated in the recent review. π βΉοΈ Recent review infoβοΈ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Plus Run ID: π Files selected for processing (3)
π WalkthroughWalkthroughThe OAuth token exchange flow now detects ChangesOAuth response handling
Estimated code review effort: 3 (Moderate) | ~20 minutes Sequence Diagram(s)sequenceDiagram
participant OAuthProvider
participant AccountSecretsHandler
participant OAuthPayloadHelpers
OAuthProvider->>AccountSecretsHandler: return token exchange payload
AccountSecretsHandler->>OAuthPayloadHelpers: detect soft failure
OAuthPayloadHelpers-->>AccountSecretsHandler: return classification
AccountSecretsHandler->>OAuthPayloadHelpers: normalize successful payload
OAuthPayloadHelpers-->>AccountSecretsHandler: return normalized payload
Possibly related PRs
π₯ Pre-merge checks | β 5β Passed checks (5 passed)
β¨ Finishing Touchesπ Generate docstrings
π§ͺ Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
π Preview deployed: https://kody-pr-1346.kody-a99.workers.dev Worker: Mocks:
|
What
Two small normalizations in the host-side
/connect/oauthtoken exchange, inoauth-token-exchange.ts+handleOAuthExchangeAction:authed_userhoisting. Slack'soauth.v2.accessnests user tokens underauthed_userβ top-levelaccess_tokenis the bot token, and is absent entirely for user-scope-only apps. The exchange response now hoistsaccess_token/refresh_token/expires_in/token_type/scopefromauthed_userto the standard top-level names when the top level lacks a token, never overwriting present fields. Standard OAuth payloads pass through untouched (same object identity).ok: falsesoft failures. Slack reports token-endpoint failures as{ ok: false, error }with HTTP 200; these now map to the standard exchange-failure response (502 + provider error string) instead of surfacing downstream as a confusing "payload did not include an access_token".Why
Community data shows
@kody/slackis the most-adopted integration package (4 forks, 2 stars) β each fork today means a user registering their own Slack app. This unblocks a platform (built-in) Slack app configured withuser_scopeviaextraAuthorizeParams, keeping token persistence provider-agnostic downstream.Testing
Unit tests for both helpers (user-scope-only hoisting, bot-token non-overwrite, standard payload passthrough, soft-failure detection).
npm run validategreen.Summary by CodeRabbit