feat: manage OAuth providers via per-provider routes#125
Merged
Conversation
Add a useOAuthProviders hook (create/update/remove) that calls the dedicated GET/POST/PATCH/DELETE /system-config/oauth-providers routes, and migrate the provider editor to it. Adding, editing, enabling, disabling, and removing a provider now apply immediately (behind the step-up guard, with confirm on remove) instead of staging into the shared config draft and replacing the whole oauth_providers array on Save. This removes the last-write-wins clobber when two admins edit providers at once. Client secrets stay out of the UI: only the clientSecretEnv variable name is entered.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Migrates the OAuth provider editor from the whole-config patch to the dedicated per-provider API routes (see fells-code/seamless-auth-api#95, reached through the adapter in fells-code/seamless-auth-server#112).
useOAuthProvidershook wrappingPOST/PATCH/DELETE /system-config/oauth-providers[/:id], each invalidating thesystem-configquery.oauth_providersarray on Save.clientSecretEnvvariable name is entered, never a raw secret.Testing
SystemConfig.test.tsxwith per-provider flow tests (create, edit-in-place on id reuse, disable, remove, remove-cancelled).