Repository navigation
feat(auth): revoke OAuth tokens at the authorization server on clear (RFC 7009) #2186
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
Merged
Changes from 18 commits
Commits
Show all changes
24 commits
Select commit
Hold shift + click to select a range
65fd2b9
feat(auth): revoke OAuth tokens at the authorization server on clear …
cliffhall 15f381c
test(auth): cover the no-window guard in getWebProxiedFetch (#2144)
cliffhall 7f27d7e
fix(auth): address Copilot review round 1 on the RFC 7009 revocation …
cliffhall 4a24c48
fix(auth): address Copilot review round 2 on the RFC 7009 revocation …
cliffhall 781aa69
fix(auth): revoke every issuer-bound grant, not just the active one (…
cliffhall 6c499f3
fix(auth): read enumerated issuers exactly, and stop the TUI tone goi…
cliffhall e9cd678
fix(auth): key grant dedup by issuer, and isolate per-slot read failu…
cliffhall 56ac830
fix(auth): RFC-encode the Basic credential; make the TUI clear await …
cliffhall 43c817c
fix(auth): bound the whole teardown, and scope the TUI clear to its s…
cliffhall 5170cc4
fix(auth): close the fail-open issuer check and the remaining clear r…
cliffhall 1661f09
fix(web): surface a failed OAuth clear instead of floating its reject…
cliffhall e2cbf0d
fix(web): lock the OAuth clear so a double click cannot run it twice …
cliffhall c0bcdc7
fix(tui): forward the clear promise from App, so AuthTab can actually…
cliffhall 69fcdd3
fix(auth): clear before waiting on the network, not after (#2144)
cliffhall 4429c0c
fix(auth): keep the failure path total, and align the docs with the n…
cliffhall a4ee263
fix(auth): refuse a grant whose authorization server cannot be establ…
cliffhall b9012da
fix: close three stale-completion holes from the round-16 suppressed …
cliffhall 0ded02b
fix(auth): revoke with the registration bound to the grant, not the c…
cliffhall 463227c
fix(auth): make snapshot-and-clear one atomic storage step (#2144)
cliffhall 579a3ee
fix(auth): salvage a malformed fallback registration, and correct the…
cliffhall 1f2e3e1
fix: address the four suppressed findings from review round 20 (#2144)
cliffhall 5ba2fad
Merge branch 'v2/main' into v2/feat/2144-oauth-revocation
cliffhall eede9c1
fix: use Node storage in the revocation e2e, and drop the now-dead st…
cliffhall c7b18ad
Merge remote-tracking branch 'origin/v2/feat/2144-oauth-revocation' i…
cliffhall File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Fixed — and this one mattered more than a name: it also still told callers to make a separate
storage.clear()call, which is exactly the second clear the atomic step exists to remove. Rewritten to describeclearAndPlanRevocation+takeRevocationSnapshot, including the explicit note that cross-process atomicity is not claimed.