(
target: {
readonly owner: Owner;
readonly name: ConnectionName;
readonly integration: IntegrationSlug;
readonly template: AuthTemplateSlug;
readonly identityLabel?: string | null;
},
client: LoadedOAuthClient,
token: OAuth2TokenResponse,
/** The scope set requested at /authorize + /token (the integration's
* declared or discovered scopes) — the recorded-scope fallback when the AS
* omits `scope`. */
requestedScopes: readonly string[],
/** The owner of `client` — persisted so refresh loads it by explicit owner. */
clientOwner: Owner,
/** Regional token endpoint override to persist when the code was redeemed
* off the client's configured host; null to use the client's token URL. */
oauthTokenUrl: string | null,
)
| 2004 | // connection row with OAuth lifecycle fields + produce its tools. |
| 2005 | // ----------------------------------------------------------------------- |
| 2006 | const mintFromToken = ( |
| 2007 | target: { |
| 2008 | readonly owner: Owner; |
| 2009 | readonly name: ConnectionName; |
| 2010 | readonly integration: IntegrationSlug; |
| 2011 | readonly template: AuthTemplateSlug; |
| 2012 | readonly identityLabel?: string | null; |
| 2013 | }, |
| 2014 | client: LoadedOAuthClient, |
| 2015 | token: OAuth2TokenResponse, |
| 2016 | /** The scope set requested at /authorize + /token (the integration's |
| 2017 | * declared or discovered scopes) — the recorded-scope fallback when the AS |
| 2018 | * omits `scope`. */ |
| 2019 | requestedScopes: readonly string[], |
| 2020 | /** The owner of `client` — persisted so refresh loads it by explicit owner. */ |
| 2021 | clientOwner: Owner, |
| 2022 | /** Regional token endpoint override to persist when the code was redeemed |
| 2023 | * off the client's configured host; null to use the client's token URL. */ |
| 2024 | oauthTokenUrl: string | null, |
| 2025 | ): Effect.Effect<Connection, StorageFailure> => |
| 2026 | Effect.gen(function* () { |
| 2027 | const provider = deps.defaultWritableProvider(); |
| 2028 | if (!provider || !provider.set) { |
| 2029 | return yield* new StorageError({ |
| 2030 | message: |
| 2031 | "No default writable credential provider is registered to store the OAuth access token.", |
| 2032 | cause: undefined, |
| 2033 | }); |
| 2034 | } |
| 2035 | const itemId = accessItemId(target.owner, target.integration, target.name); |
| 2036 | yield* provider.set(ProviderItemId.make(itemId), token.access_token); |
| 2037 | |
| 2038 | let refreshItemId: string | null = null; |
| 2039 | if (token.refresh_token) { |
| 2040 | refreshItemId = refreshItemIdFor(itemId); |
| 2041 | yield* provider.set(ProviderItemId.make(refreshItemId), token.refresh_token); |
| 2042 | } |
| 2043 | |
| 2044 | const oauthScope = recordedOAuthScope(token, requestedScopes); |
| 2045 | const missingScopes = |
| 2046 | client.grant === "authorization_code" |
| 2047 | ? missingGrantedOAuthScopes(requestedScopes, oauthScope) |
| 2048 | : []; |
| 2049 | // The freshness facts of this connection AT BIRTH, on the enclosing |
| 2050 | // span (executor.oauth.complete, or the reconnect path's request |
| 2051 | // envelope). Every "why did this connection later go stale" question |
| 2052 | // starts here: a partial grant fails later as oauth_scope_insufficient |
| 2053 | // in an unrelated trace; no refresh token means the first expiry is |
| 2054 | // terminal; no advertised expiry means only the reactive 401 path can |
| 2055 | // ever refresh it. Counts and booleans only — scope VALUES can encode |
| 2056 | // customer resource names on some providers. |
| 2057 | yield* Effect.annotateCurrentSpan({ |
| 2058 | "executor.oauth.scope_requested_count": requestedScopes.length, |
| 2059 | "executor.oauth.scope_missing_count": missingScopes.length, |
| 2060 | "executor.oauth.has_refresh_token": token.refresh_token !== undefined, |
| 2061 | "executor.oauth.has_advertised_expiry": typeof token.expires_in === "number", |
| 2062 | }); |
| 2063 | return yield* deps.mintOAuthConnection({ |
no test coverage detected