| 96 | * runs through untouched. |
| 97 | */ |
| 98 | const makeTokenRequestPark = () => { |
| 99 | let armed = false; |
| 100 | let onSeen: (() => void) | null = null; |
| 101 | const seen = new Promise<void>((resolve) => { |
| 102 | onSeen = resolve; |
| 103 | }); |
| 104 | let onRelease: (() => void) | null = null; |
| 105 | const parked = new Promise<void>((resolve) => { |
| 106 | onRelease = resolve; |
| 107 | }); |
| 108 | // oxlint-disable-next-line executor/no-raw-fetch -- test boundary: the park wraps the platform fetch and must delegate back to it, which is the only seam that can hold a token request open mid-grant. |
| 109 | const platformFetch: typeof globalThis.fetch = globalThis.fetch; |
| 110 | const fetch: typeof globalThis.fetch = async (input, init) => { |
| 111 | const response = await platformFetch(input, init); |
| 112 | if (armed && new URL(fetchTarget(input)).pathname === "/token") { |
| 113 | onSeen?.(); |
| 114 | await parked; |
| 115 | } |
| 116 | return response; |
| 117 | }; |
| 118 | return { |
| 119 | fetch, |
| 120 | arm: () => { |
| 121 | armed = true; |
| 122 | }, |
| 123 | /** Resolves once a token request has been answered and is being held. */ |
| 124 | seen, |
| 125 | release: () => onRelease?.(), |
| 126 | }; |
| 127 | }; |
| 128 | |
| 129 | /** Every refresh-token grant the authorization server was asked for. */ |
| 130 | const refreshGrantsIn = ( |