Skip to content

Default token_type to Bearer on client_credentials responses - #2184

Closed
deepanshupal wants to merge 3 commits into
UsefulSoftwareCo:mainfrom
deepanshupal:fix/client-credentials-default-token-type
Closed

deepanshupal wants to merge 3 commits into
UsefulSoftwareCo:mainfrom
deepanshupal:fix/client-credentials-default-token-type

Conversation

@deepanshupal

Copy link
Copy Markdown

Refs #2090. Implements the fix offered in my comment on that issue before it was closed. Shopify's Admin API answers a client_credentials grant with only access_token, scope and expires_in, and oauth4webapi rejects it because RFC 6749 requires token_type. This defaults it to Bearer for the client_credentials grant only and reads a comma-separated scope as a list; responses with a token_type are unchanged. Test: Shopify-shaped response (fails before, passes after) and an explicit token_type case. oauth-helpers tests 98/98; the 13 oxlint-plugin test failures in the sdk package also fail on clean main in my environment. Lint, format check and e2e not run.

@RhysSullivan

Copy link
Copy Markdown
Collaborator

We're clearing the backlog ahead of the v2 launch, so we're closing this. If it still applies to v2, please open a new issue or PR against v2.

Sent from my Claude

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants