MCPcopy Create free account
hub / github.com/UsefulSoftwareCo/executor / complete

Function complete

packages/core/sdk/src/oauth-service.ts:1376–1544  ·  view source on GitHub ↗
(
    input: OAuthCompleteInput,
  )

Source from the content-addressed store, hash-verified

1374 // complete — redeem the session, exchange the code, mint the connection.
1375 // -----------------------------------------------------------------------
1376 const complete = (
1377 input: OAuthCompleteInput,
1378 ): Effect.Effect<Connection, OAuthCompleteError | OAuthSessionNotFoundError | StorageFailure> =>
1379 Effect.gen(function* () {
1380 const sessionRow = yield* deps.fuma.use("oauth_session.findFirst", (db) =>
1381 looseDb(db).findFirst("oauth_session", {
1382 where: (b: any) => b("state", "=", String(input.state)),
1383 }),
1384 );
1385 if (!sessionRow) {
1386 return yield* new OAuthSessionNotFoundError({ state: input.state });
1387 }
1388 const session = {
1389 owner: String(sessionRow.owner) as Owner,
1390 clientSlug: OAuthClientSlug.make(String(sessionRow.client_slug)),
1391 integration: IntegrationSlug.make(String(sessionRow.integration)),
1392 name: ConnectionName.make(String(sessionRow.name)),
1393 template: AuthTemplateSlug.make(String(sessionRow.template)),
1394 redirectUrl: String(sessionRow.redirect_url),
1395 pkceVerifier: sessionRow.pkce_verifier == null ? null : String(sessionRow.pkce_verifier),
1396 identityLabel: sessionRow.identity_label == null ? null : String(sessionRow.identity_label),
1397 expiresAt: Number(sessionRow.expires_at),
1398 // The scope set `start` requested (the integration's declared or
1399 // discovered scopes), persisted on the session payload. Drives the
1400 // recorded-scope fallback when the AS omits `scope`. Missing/legacy
1401 // payloads fall back to the client's scopes below.
1402 requestedScopes: requestedScopesFromPayload(sessionRow.payload),
1403 // The app's owner, recorded by `start` — reload the SAME app at
1404 // completion by explicit owner (no derivation). Defaults to the session
1405 // owner for same-owner connects.
1406 clientOwner:
1407 clientOwnerFromPayload(sessionRow.payload) ?? (String(sessionRow.owner) as Owner),
1408 };
1409
1410 // Annotate as soon as the session resolves the flow's identity, so even
1411 // a completion that fails at the exchange still says WHOSE connect died.
1412 yield* Effect.annotateCurrentSpan({
1413 "executor.integration": String(session.integration),
1414 "executor.connection": String(session.name),
1415 "executor.template": String(session.template),
1416 "executor.oauth.client": String(session.clientSlug),
1417 "executor.oauth.client_first_party": isFirstPartyOAuthClientSlug(
1418 String(session.clientSlug),
1419 ),
1420 });
1421
1422 // Expired sessions are not redeemable — drop + treat as not found.
1423 if (Number.isFinite(session.expiresAt) && session.expiresAt <= Date.now()) {
1424 yield* deleteSession(input.state);
1425 return yield* new OAuthSessionNotFoundError({ state: input.state });
1426 }
1427
1428 // Reload the SAME app `start` resolved, by its explicit recorded owner.
1429 const client = yield* loadClient(session.clientOwner, session.clientSlug);
1430 if (!client) {
1431 return yield* new OAuthCompleteError({
1432 message: `OAuth client not found: ${session.clientSlug}`,
1433 restartRequired: true,

Callers

nothing calls this directly

Calls 11

looseDbFunction · 0.85
clientOwnerFromPayloadFunction · 0.85
deleteSessionFunction · 0.85
loadClientFunction · 0.85
mintFromTokenFunction · 0.85
getMethod · 0.65

Tested by

no test coverage detected