Skip to content

feat(oauth): incremental scope and service consent - #1718

Merged
ctkm-aelf merged 2 commits into
mainfrom
codex/incremental-oauth-consent-1682
Sep 30, 2026
Merged

ctkm-aelf merged 2 commits into
mainfrom
codex/incremental-oauth-consent-1682

Conversation

@ctkm-aelf

@ctkm-aelf ctkm-aelf commented Sep 30, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

  • Add additive OAuth authorization with include_granted_scopes=true: newly approved scopes and exact UserService IDs extend the existing grant while RFC 8707 resource can narrow the issued access token. Signed review snapshots, live service ACLs, grant-version checks, and revocation fences protect the update.
  • Add the NyxID Update service access page with required additions, optional selections, read-only existing access, and explicit error, expiry, and unavailable-service states. Return protocol-correct OAuth errors for invalid requests and revoked authorization codes.
  • Expose incremental requests through the core/React SDKs and document scope-only and service-only requests, PKCE, callback state validation, and the Aevatar integration boundary.

Refs #1682. This PR is a separate NyxID implementation and supersedes #1683; the original implementation is credited in the commit. Keep #1682 open until Aevatar completes its Services entry point, callback, draft restoration, and cross-application acceptance.

Test Plan

  • Backend OAuth handler tests against MongoDB 8 replica set: cargo test -p nyxid --bin nyxid-server handlers::oauth::tests -- --test-threads=2 (77 passed)
  • Frontend consent tests: npm test -- src/pages/oauth-incremental-consent.test.tsx src/pages/oauth-consent.test.tsx (49 passed)
  • Core SDK tests: npm test (17 passed); core and React SDK TypeScript builds passed
  • Frontend TypeScript, changed-file ESLint/Prettier, cargo fmt --all -- --check, and git diff --check
  • Signed local consent flow reviewed with existing and newly requested service access

Checklist

  • Code follows the project's architecture rules
  • No hardcoded secrets or credentials
  • OAuth errors do not leak internal details
  • Developer documentation updated

ctkm-aelf and others added 2 commits October 1, 2026 06:51
Preserve prior grants while authorizing added OAuth scopes and exact services. Add the consent review, SDK request support, protocol error handling, tests, and developer guidance.

Refs #1682.

Co-authored-by: Abigail Deng <108705114+AbigailDeng@users.noreply.github.com>
@github-actions

github-actions Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

📊 Code coverage

Component Lines Threshold Status Δ vs base
Backend (nyxid) 87.49% 73% ✅ 🔺 +0.05
Frontend (vitest) 71.04% 15% ✅ 🔺 +0.03

Gate: line coverage must stay at or above the threshold. Ratchet plan (W21): Backend → 55%, CLI → 50%, Frontend → 30% by quarter end.

@ctkm-aelf
ctkm-aelf merged commit edf9ba8 into main Sep 30, 2026
34 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant