(
owner: Owner,
slug: OAuthClientSlug,
)
| 1239 | // Load an oauth_client row by (owner, slug). |
| 1240 | // ----------------------------------------------------------------------- |
| 1241 | const loadClient = ( |
| 1242 | owner: Owner, |
| 1243 | slug: OAuthClientSlug, |
| 1244 | ): Effect.Effect<LoadedOAuthClient | null, StorageFailure> => { |
| 1245 | // First-party apps resolve from config, never storage. Owner is irrelevant: |
| 1246 | // the app belongs to the DEPLOYMENT, and visibility policy has nothing to |
| 1247 | // narrow — only the minted connection (and its tokens) is owner-scoped. |
| 1248 | if (isFirstPartyOAuthClientSlug(String(slug))) { |
| 1249 | const config = firstPartyBySlug.get(String(slug)); |
| 1250 | return Effect.succeed(config ? loadedFirstPartyClient(config) : null); |
| 1251 | } |
| 1252 | return deps.fuma |
| 1253 | .use("oauth_client.findFirst", (db) => |
| 1254 | looseDb(db).findFirst("oauth_client", { |
| 1255 | where: (b: any) => b.and(b("owner", "=", owner), b("slug", "=", String(slug))), |
| 1256 | }), |
| 1257 | ) |
| 1258 | .pipe( |
| 1259 | Effect.flatMap((row) => { |
| 1260 | if (!row) return Effect.succeed(null); |
| 1261 | const grant = parseGrant(row.grant); |
| 1262 | // EXPLICIT — this row drives the token exchange. An unknown grant is a |
| 1263 | // corrupt row; fail loudly rather than guessing authorization_code and |
| 1264 | // running the wrong flow. |
| 1265 | if (grant === null) { |
| 1266 | return Effect.fail( |
| 1267 | new StorageError({ |
| 1268 | message: `oauth_client ${String(slug)} has an unknown grant: ${String(row.grant)}`, |
| 1269 | cause: undefined, |
| 1270 | }), |
| 1271 | ); |
| 1272 | } |
| 1273 | // `client_secret_item_id` is null for DCR-minted / public PKCE clients; |
| 1274 | // the token exchange treats a missing secret as "public client, omit |
| 1275 | // client_secret" (see pickClientAuth). A confidential client persisted |
| 1276 | // its secret to the provider in createClient; resolve it back here. |
| 1277 | return Effect.gen(function* () { |
| 1278 | let clientSecret = ""; |
| 1279 | if (row.client_secret_item_id != null) { |
| 1280 | const provider = deps.defaultWritableProvider(); |
| 1281 | if (provider) { |
| 1282 | clientSecret = |
| 1283 | (yield* provider.get(ProviderItemId.make(String(row.client_secret_item_id)))) ?? |
| 1284 | ""; |
| 1285 | } |
| 1286 | } |
| 1287 | return { |
| 1288 | slug: String(row.slug), |
| 1289 | authorizationUrl: String(row.authorization_url), |
| 1290 | tokenUrl: String(row.token_url), |
| 1291 | grant, |
| 1292 | clientId: String(row.client_id), |
| 1293 | clientSecret, |
| 1294 | resource: row.resource == null ? null : String(row.resource), |
| 1295 | } satisfies LoadedOAuthClient; |
| 1296 | }); |
| 1297 | }), |
| 1298 | ); |
no test coverage detected