(input: {
readonly grantType:
| "authorization_code"
| "client_credentials"
| "refresh_token"
| typeof TOKEN_EXCHANGE_GRANT_TYPE
| typeof JWT_BEARER_GRANT_TYPE;
readonly tokenUrl: string;
readonly clientAuth: ClientAuthMethod | undefined;
readonly hasResource: boolean;
})
| 630 | * response URL and a body preview), never token or code material. */ |
| 631 | const withTokenRequestSpan = |
| 632 | (input: { |
| 633 | readonly grantType: |
| 634 | | "authorization_code" |
| 635 | | "client_credentials" |
| 636 | | "refresh_token" |
| 637 | | typeof TOKEN_EXCHANGE_GRANT_TYPE |
| 638 | | typeof JWT_BEARER_GRANT_TYPE; |
| 639 | readonly tokenUrl: string; |
| 640 | readonly clientAuth: ClientAuthMethod | undefined; |
| 641 | readonly hasResource: boolean; |
| 642 | }) => |
| 643 | <A>(effect: Effect.Effect<A, OAuth2Error>): Effect.Effect<A, OAuth2Error> => |
| 644 | effect.pipe( |
| 645 | Effect.tapError((error) => |
| 646 | Effect.annotateCurrentSpan({ |
| 647 | ...(error.error !== undefined ? { "executor.oauth.error_code": error.error } : {}), |
| 648 | }), |
| 649 | ), |
| 650 | Effect.withSpan("executor.oauth.token_request", { |
| 651 | attributes: { |
| 652 | "executor.oauth.grant_type": input.grantType, |
| 653 | "executor.oauth.token_host": hostnameForTelemetry(input.tokenUrl), |
| 654 | "executor.oauth.client_auth": input.clientAuth ?? DEFAULT_CLIENT_AUTH_METHOD, |
| 655 | "executor.oauth.has_resource": input.hasResource, |
| 656 | }, |
| 657 | }), |
| 658 | ); |
| 659 | |
| 660 | /** The hostname alone — a malformed URL yields "invalid" rather than leaking |
| 661 | * whatever string failed to parse. */ |
no test coverage detected