(
owner: Owner,
slug: OAuthClientSlug,
)
| 1337 | // Load an oauth_client row by (owner, slug). |
| 1338 | // ----------------------------------------------------------------------- |
| 1339 | const loadClient = ( |
| 1340 | owner: Owner, |
| 1341 | slug: OAuthClientSlug, |
| 1342 | ): Effect.Effect<LoadedOAuthClient | null, StorageFailure> => { |
| 1343 | // First-party apps resolve from config, never storage. Owner is irrelevant: |
| 1344 | // the app belongs to the DEPLOYMENT, and visibility policy has nothing to |
| 1345 | // narrow — only the minted connection (and its tokens) is owner-scoped. |
| 1346 | if (isFirstPartyOAuthClientSlug(String(slug))) { |
| 1347 | const config = firstPartyBySlug.get(String(slug)); |
| 1348 | return Effect.succeed(config ? loadedFirstPartyClient(config) : null); |
| 1349 | } |
| 1350 | return deps.fuma |
| 1351 | .use("oauth_client.findFirst", (db) => |
| 1352 | looseDb(db).findFirst("oauth_client", { |
| 1353 | where: (b: any) => b.and(b("owner", "=", owner), b("slug", "=", String(slug))), |
| 1354 | }), |
| 1355 | ) |
| 1356 | .pipe( |
| 1357 | Effect.flatMap((row) => { |
| 1358 | if (!row) return Effect.succeed(null); |
| 1359 | const grant = parseGrant(row.grant); |
| 1360 | // EXPLICIT — this row drives the token exchange. An unknown grant is a |
| 1361 | // corrupt row; fail loudly rather than guessing authorization_code and |
| 1362 | // running the wrong flow. |
| 1363 | if (grant === null) { |
| 1364 | return Effect.fail( |
| 1365 | new StorageError({ |
| 1366 | message: `oauth_client ${String(slug)} has an unknown grant: ${String(row.grant)}`, |
| 1367 | cause: undefined, |
| 1368 | }), |
| 1369 | ); |
| 1370 | } |
| 1371 | // `client_secret_item_id` is null for DCR-minted / public PKCE clients; |
| 1372 | // the token exchange treats a missing secret as "public client, omit |
| 1373 | // client_secret" (see pickClientAuth). A confidential client persisted |
| 1374 | // its secret to the provider in createClient; resolve it back here. |
| 1375 | return Effect.gen(function* () { |
| 1376 | let clientSecret = ""; |
| 1377 | if (row.client_secret_item_id != null) { |
| 1378 | const provider = deps.defaultWritableProvider(); |
| 1379 | if (provider) { |
| 1380 | clientSecret = |
| 1381 | (yield* provider.get(ProviderItemId.make(String(row.client_secret_item_id)))) ?? |
| 1382 | ""; |
| 1383 | } |
| 1384 | } |
| 1385 | return { |
| 1386 | slug: String(row.slug), |
| 1387 | authorizationUrl: String(row.authorization_url), |
| 1388 | tokenUrl: String(row.token_url), |
| 1389 | grant, |
| 1390 | clientId: String(row.client_id), |
| 1391 | clientSecret, |
| 1392 | resource: row.resource == null ? null : String(row.resource), |
| 1393 | } satisfies LoadedOAuthClient; |
| 1394 | }); |
| 1395 | }), |
| 1396 | ); |
no test coverage detected