MCPcopy Create free account
hub / github.com/UsefulSoftwareCo/executor / mintFromToken

Function mintFromToken

packages/core/sdk/src/oauth-service.ts:1410–1490  ·  view source on GitHub ↗
(
    target: {
      readonly owner: Owner;
      readonly name: ConnectionName;
      readonly integration: IntegrationSlug;
      readonly template: AuthTemplateSlug;
      readonly identityLabel?: string | null;
    },
    client: LoadedOAuthClient,
    token: OAuth2TokenResponse,
    /** The scope set requested at /authorize + /token (the integration's
     *  declared or discovered scopes) — the recorded-scope fallback when the AS
     *  omits `scope`. */
    requestedScopes: readonly string[],
    /** The owner of `client` — persisted so refresh loads it by explicit owner. */
    clientOwner: Owner,
    /** Regional token endpoint override to persist when the code was redeemed
     *  off the client's configured host; null to use the client's token URL. */
    oauthTokenUrl: string | null,
  )

Source from the content-addressed store, hash-verified

1408 // connection row with OAuth lifecycle fields + produce its tools.
1409 // -----------------------------------------------------------------------
1410 const mintFromToken = (
1411 target: {
1412 readonly owner: Owner;
1413 readonly name: ConnectionName;
1414 readonly integration: IntegrationSlug;
1415 readonly template: AuthTemplateSlug;
1416 readonly identityLabel?: string | null;
1417 },
1418 client: LoadedOAuthClient,
1419 token: OAuth2TokenResponse,
1420 /** The scope set requested at /authorize + /token (the integration's
1421 * declared or discovered scopes) — the recorded-scope fallback when the AS
1422 * omits `scope`. */
1423 requestedScopes: readonly string[],
1424 /** The owner of `client` — persisted so refresh loads it by explicit owner. */
1425 clientOwner: Owner,
1426 /** Regional token endpoint override to persist when the code was redeemed
1427 * off the client's configured host; null to use the client's token URL. */
1428 oauthTokenUrl: string | null,
1429 ): Effect.Effect<Connection, StorageFailure> =>
1430 Effect.gen(function* () {
1431 const provider = deps.defaultWritableProvider();
1432 if (!provider || !provider.set) {
1433 return yield* new StorageError({
1434 message:
1435 "No default writable credential provider is registered to store the OAuth access token.",
1436 cause: undefined,
1437 });
1438 }
1439 const itemId = accessItemId(target.owner, target.integration, target.name);
1440 yield* provider.set(ProviderItemId.make(itemId), token.access_token);
1441
1442 let refreshItemId: string | null = null;
1443 if (token.refresh_token) {
1444 refreshItemId = refreshItemIdFor(itemId);
1445 yield* provider.set(ProviderItemId.make(refreshItemId), token.refresh_token);
1446 }
1447
1448 const oauthScope = recordedOAuthScope(token, requestedScopes);
1449 const missingScopes =
1450 client.grant === "authorization_code"
1451 ? missingGrantedOAuthScopes(requestedScopes, oauthScope)
1452 : [];
1453 // The freshness facts of this connection AT BIRTH, on the enclosing
1454 // span (executor.oauth.complete, or the reconnect path's request
1455 // envelope). Every "why did this connection later go stale" question
1456 // starts here: a partial grant fails later as oauth_scope_insufficient
1457 // in an unrelated trace; no refresh token means the first expiry is
1458 // terminal; no advertised expiry means only the reactive 401 path can
1459 // ever refresh it. Counts and booleans only — scope VALUES can encode
1460 // customer resource names on some providers.
1461 yield* Effect.annotateCurrentSpan({
1462 "executor.oauth.scope_requested_count": requestedScopes.length,
1463 "executor.oauth.scope_missing_count": missingScopes.length,
1464 "executor.oauth.has_refresh_token": token.refresh_token !== undefined,
1465 "executor.oauth.has_advertised_expiry": typeof token.expires_in === "number",
1466 });
1467 return yield* deps.mintOAuthConnection({

Callers 2

startFunction · 0.85
completeFunction · 0.85

Calls 6

accessItemIdFunction · 0.85
refreshItemIdForFunction · 0.85
recordedOAuthScopeFunction · 0.85
expiresAtFromFunction · 0.85
setMethod · 0.80

Tested by

no test coverage detected