Repository navigation
Conversation
|
| } | ||
|
|
||
| /** | ||
| * Create a token for an installation of an application. Requires an app key sent in the `X-Appwrite-Key` header alongside the `X-Appwrite-App` header, or a caller with update access to the app. The returned token carries the scopes and authorization details granted to the installation, and can be used as an `Authorization: Bearer` header everywhere OAuth2 access tokens are accepted. Multiple tokens can be active for the same installation at once; each token stays valid until it expires or the installation is updated or deleted. |
There was a problem hiding this comment.
This method says callers can use an app key, but the request sends neither X-Appwrite-Key nor X-Appwrite-App, and Client has no setter for either. A caller following this API and its example cannot use the documented app-key path without directly modifying client.headers. Please document a supported way to supply those credentials, or direct callers to an appropriate server-side SDK.
Prompt To Fix With AI
This is a comment left during a code review.
Path: src/services/apps.ts
Line: 1081
Comment:
**App-key usage is unclear**
This method says callers can use an app key, but the request sends neither `X-Appwrite-Key` nor `X-Appwrite-App`, and `Client` has no setter for either. A caller following this API and its example cannot use the documented app-key path without directly modifying `client.headers`. Please document a supported way to supply those credentials, or direct callers to an appropriate server-side SDK.
---
For each issue above, determine whether it is valid and should be fixed. If so, fix it directly.| const apiHeaders: { [header: string]: string } = { | ||
| 'content-type': 'application/json', | ||
| accept: 'application/json', | ||
| }; | ||
|
|
||
| return this.client.call('post', uri, apiHeaders, payload); |
There was a problem hiding this comment.
Token flows lack behavior tests
The new token exchange supports authorization-code, refresh-token, and device-code flows, but none has a behavior test. Tests covering the requests and responses for each flow would catch credential or serialization regressions. Please test observable behavior rather than mirroring method bodies, configuration, or version strings.
Prompt To Fix With AI
This is a comment left during a code review.
Path: src/services/oauth-2.ts
Line: 1815-1820
Comment:
**Token flows lack behavior tests**
The new token exchange supports authorization-code, refresh-token, and device-code flows, but none has a behavior test. Tests covering the requests and responses for each flow would catch credential or serialization regressions. Please test observable behavior rather than mirroring method bodies, configuration, or version strings.
---
For each issue above, determine whether it is valid and should be fixed. If so, fix it directly.Note: If this suggestion doesn't match your team's coding style, reply to this and let me know. I'll remember it for next time!
This PR contains updates to the SDK for version 28.1.0.
What's Changed
Appsservice to create and manage OAuth2 apps, their secrets, keys, and installationsOauth2service for authorization, consent, device, PAR, and token flowsApp,AppSecret,AppKey,AppScopeandOauth2*response models