(input: {
readonly grantType:
| "authorization_code"
| "client_credentials"
| "refresh_token"
| typeof TOKEN_EXCHANGE_GRANT_TYPE
| typeof JWT_BEARER_GRANT_TYPE;
readonly tokenUrl: string;
readonly clientAuth: ClientAuthMethod | undefined;
readonly hasResource: boolean;
})
| 807 | * response URL and a body preview), never token or code material. */ |
| 808 | const withTokenRequestSpan = |
| 809 | (input: { |
| 810 | readonly grantType: |
| 811 | | "authorization_code" |
| 812 | | "client_credentials" |
| 813 | | "refresh_token" |
| 814 | | typeof TOKEN_EXCHANGE_GRANT_TYPE |
| 815 | | typeof JWT_BEARER_GRANT_TYPE; |
| 816 | readonly tokenUrl: string; |
| 817 | readonly clientAuth: ClientAuthMethod | undefined; |
| 818 | readonly hasResource: boolean; |
| 819 | }) => |
| 820 | <A>(effect: Effect.Effect<A, OAuth2Error>): Effect.Effect<A, OAuth2Error> => |
| 821 | effect.pipe( |
| 822 | Effect.tapError((error) => |
| 823 | Effect.annotateCurrentSpan({ |
| 824 | ...(error.error !== undefined ? { "executor.oauth.error_code": error.error } : {}), |
| 825 | }), |
| 826 | ), |
| 827 | Effect.withSpan("executor.oauth.token_request", { |
| 828 | attributes: { |
| 829 | "executor.oauth.grant_type": input.grantType, |
| 830 | "executor.oauth.token_host": hostnameForTelemetry(input.tokenUrl), |
| 831 | "executor.oauth.client_auth": input.clientAuth ?? DEFAULT_CLIENT_AUTH_METHOD, |
| 832 | "executor.oauth.has_resource": input.hasResource, |
| 833 | }, |
| 834 | }), |
| 835 | ); |
| 836 | |
| 837 | /** The hostname alone — a malformed URL yields "invalid" rather than leaking |
| 838 | * whatever string failed to parse. */ |
no test coverage detected