Skip to content

Default token_type to Bearer on client_credentials responses - #2184

Open
DeepanshuPal wants to merge 3 commits into
UsefulSoftwareCo:mainfrom
DeepanshuPal:fix/client-credentials-default-token-type
Open

DeepanshuPal wants to merge 3 commits into
UsefulSoftwareCo:mainfrom
DeepanshuPal:fix/client-credentials-default-token-type

Conversation

@DeepanshuPal

Copy link
Copy Markdown

Refs #2090. Implements the fix offered in my comment on that issue before it was closed. Shopify's Admin API answers a client_credentials grant with only access_token, scope and expires_in, and oauth4webapi rejects it because RFC 6749 requires token_type. This defaults it to Bearer for the client_credentials grant only and reads a comma-separated scope as a list; responses with a token_type are unchanged. Test: Shopify-shaped response (fails before, passes after) and an explicit token_type case. oauth-helpers tests 98/98; the 13 oxlint-plugin test failures in the sdk package also fail on clean main in my environment. Lint, format check and e2e not run.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant