(
owner: Owner,
slug: OAuthClientSlug,
)
| 1071 | // Load an oauth_client row by (owner, slug). |
| 1072 | // ----------------------------------------------------------------------- |
| 1073 | const loadClient = ( |
| 1074 | owner: Owner, |
| 1075 | slug: OAuthClientSlug, |
| 1076 | ): Effect.Effect<LoadedOAuthClient | null, StorageFailure> => { |
| 1077 | // First-party apps resolve from config, never storage. Owner is irrelevant: |
| 1078 | // the app belongs to the DEPLOYMENT, and visibility policy has nothing to |
| 1079 | // narrow — only the minted connection (and its tokens) is owner-scoped. |
| 1080 | if (isFirstPartyOAuthClientSlug(String(slug))) { |
| 1081 | const config = firstPartyBySlug.get(String(slug)); |
| 1082 | return Effect.succeed(config ? loadedFirstPartyClient(config) : null); |
| 1083 | } |
| 1084 | return deps.fuma |
| 1085 | .use("oauth_client.findFirst", (db) => |
| 1086 | looseDb(db).findFirst("oauth_client", { |
| 1087 | where: (b: any) => b.and(b("owner", "=", owner), b("slug", "=", String(slug))), |
| 1088 | }), |
| 1089 | ) |
| 1090 | .pipe( |
| 1091 | Effect.flatMap((row) => { |
| 1092 | if (!row) return Effect.succeed(null); |
| 1093 | const grant = parseGrant(row.grant); |
| 1094 | // EXPLICIT — this row drives the token exchange. An unknown grant is a |
| 1095 | // corrupt row; fail loudly rather than guessing authorization_code and |
| 1096 | // running the wrong flow. |
| 1097 | if (grant === null) { |
| 1098 | return Effect.fail( |
| 1099 | new StorageError({ |
| 1100 | message: `oauth_client ${String(slug)} has an unknown grant: ${String(row.grant)}`, |
| 1101 | cause: undefined, |
| 1102 | }), |
| 1103 | ); |
| 1104 | } |
| 1105 | // `client_secret_item_id` is null for DCR-minted / public PKCE clients; |
| 1106 | // the token exchange treats a missing secret as "public client, omit |
| 1107 | // client_secret" (see pickClientAuth). A confidential client persisted |
| 1108 | // its secret to the provider in createClient; resolve it back here. |
| 1109 | return Effect.gen(function* () { |
| 1110 | let clientSecret = ""; |
| 1111 | if (row.client_secret_item_id != null) { |
| 1112 | const provider = deps.defaultWritableProvider(); |
| 1113 | if (provider) { |
| 1114 | clientSecret = |
| 1115 | (yield* provider.get(ProviderItemId.make(String(row.client_secret_item_id)))) ?? |
| 1116 | ""; |
| 1117 | } |
| 1118 | } |
| 1119 | return { |
| 1120 | slug: String(row.slug), |
| 1121 | authorizationUrl: String(row.authorization_url), |
| 1122 | tokenUrl: String(row.token_url), |
| 1123 | grant, |
| 1124 | clientId: String(row.client_id), |
| 1125 | clientSecret, |
| 1126 | resource: row.resource == null ? null : String(row.resource), |
| 1127 | } satisfies LoadedOAuthClient; |
| 1128 | }); |
| 1129 | }), |
| 1130 | ); |
no test coverage detected