- migration 0005 oauth_states: one-time states (10-min TTL), consumed by a CAS DELETE on callback — replays and forgeries both 404 - POST /api/apps/oauth/start: OIDC discovery on the configured issuer (or the custom MCP issuer for authType=mcp_oauth), state row, authorize URL - GET /api/apps/oauth/callback: code exchanged at the REAL token endpoint (client id+secret form POST); the access token goes straight to the broker (test proves it never appears unencrypted in Postgres); connection row + audit; redirects to the claw's Add Apps panel - [oauth] config (issuer/client/redirect_base) wired through AppState - Tests against a real local IdP server (discovery + validating token endpoint): full round trip, broker-held token, replay/forged state refused, bad code fails exchange, mcp_oauth uses the custom issuer while plain oauth refuses without a configured IdP - AddAppsApp: live connection badges + inline API-key connect per app (E2E: connect Notion by key from the directory) 136 Rust + 63 frontend tests + 21 Playwright journeys. Co-Authored-By: Claude Fable 5 <[email protected]>
21 lines
558 B
JSON
21 lines
558 B
JSON
{
|
|
"db_name": "PostgreSQL",
|
|
"query": "INSERT INTO oauth_states\n (state, workspace_id, user_id, agent_id, provider, auth_type,\n issuer_url, expires_at)\n VALUES ($1, $2, $3, $4, $5, $6, $7, now() + interval '10 minutes')",
|
|
"describe": {
|
|
"columns": [],
|
|
"parameters": {
|
|
"Left": [
|
|
"Text",
|
|
"Uuid",
|
|
"Uuid",
|
|
"Uuid",
|
|
"Text",
|
|
"Text",
|
|
"Text"
|
|
]
|
|
},
|
|
"nullable": []
|
|
},
|
|
"hash": "b53b31468a210a8055710c4f17c41b66cf409b3299f32bc00e3beb164f58f4e7"
|
|
}
|