Repository navigation
Activate descriptor-backed PKCE refresh - #449
Merged
Merged
Conversation
adamcik
added this pull request to stack #453
September 23, 2026 15:14
adamcik
force-pushed
the
oauth-runtime-integration
branch
from
September 23, 2026 21:30
20108ea to
f1d6c4c
Compare
adamcik
force-pushed
the
oauth-runtime-integration
branch
from
September 24, 2026 18:54
f1d6c4c to
f55eec5
Compare
adamcik
force-pushed
the
oauth-runtime-integration
branch
from
September 24, 2026 20:57
f55eec5 to
3df9eef
Compare
adamcik
force-pushed
the
oauth-runtime-integration
branch
from
September 24, 2026 21:09
3df9eef to
b3b6f26
Compare
adamcik
force-pushed
the
oauth-runtime-integration
branch
2 times, most recently
from
September 24, 2026 21:53
67b95fd to
d2073c5
Compare
adamcik
force-pushed
the
oauth-runtime-integration
branch
from
September 24, 2026 22:08
d2073c5 to
db2d819
Compare
adamcik
force-pushed
the
oauth-runtime-integration
branch
2 times, most recently
from
September 26, 2026 22:53
8c1d155 to
ef0212d
Compare
adamcik
force-pushed
the
oauth-runtime-integration
branch
from
September 26, 2026 23:06
ef0212d to
b61f586
Compare
adamcik
force-pushed
the
oauth-runtime-integration
branch
from
September 26, 2026 23:10
b61f586 to
91b2c7c
Compare
adamcik
force-pushed
the
oauth-runtime-integration
branch
4 times, most recently
from
September 27, 2026 10:24
7e5d24b to
4134396
Compare
adamcik
force-pushed
the
oauth-runtime-integration
branch
2 times, most recently
from
September 27, 2026 11:36
f4e47cd to
2e2aca3
Compare
adamcik
force-pushed
the
oauth-runtime-integration
branch
from
September 27, 2026 11:54
2e2aca3 to
6967dd8
Compare
adamcik
force-pushed
the
oauth-runtime-integration
branch
2 times, most recently
from
October 3, 2026 12:12
695a46c to
7d23b07
Compare
jodal
force-pushed
the
oauth-runtime-integration
branch
3 times, most recently
from
October 3, 2026 12:26
08fe2d6 to
7b845fd
Compare
jodal
force-pushed
the
oauth-runtime-integration
branch
from
October 3, 2026 12:28
7b845fd to
69cfc4f
Compare
adamcik
force-pushed
the
oauth-runtime-integration
branch
2 times, most recently
from
October 4, 2026 19:29
1386fbe to
9ada8b7
Compare
Load resolved authorization snapshots at runtime and persist provider transitions with compare-and-set semantics. Preserve legacy bridge fallback while preventing stale refresh responses from overwriting newer authorization.
adamcik
force-pushed
the
oauth-runtime-integration
branch
from
October 4, 2026 19:59
9ada8b7 to
a188c50
Compare
adamcik
marked this pull request as ready for review
October 4, 2026 20:01
adamcik
removed this pull request from stack #453
October 4, 2026 20:28
adamcik
added this pull request to stack #455
October 4, 2026 20:30
jodal
approved these changes
Oct 5, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The authorization store and refresh policies are already on
main; this PR connects them to the running Web client. Playback authorization is unchanged.Review path
backend.pywires the store, PKCE provider, and bridge provider intoSpotifyAccessTokenSource.oauth/source.pyowns the refresh transaction shown below. The network request runs without the store lock. Selecting a provider is the only opportunity for fallback; a failed exchange does not try another grant.oauth/providers.pycontains the grant differences: PKCE retains or rotates its refresh token; the bridge uses configured credentials and ignores refresh tokens in its response.web.pyinstalls the access token only after the source returns successfully.flowchart TD A[Load authorization snapshot] --> B[Select provider] B -->|PKCE authorized| C[PKCE request] B -->|Missing, cleared, or bridge state| D[Bridge request if configured] B -->|PKCE rejected or no provider| X[Stop without an exchange] C --> E[Exchange and validate response] D --> E E --> F[Provider processes response] F -->|Transient failure| G[Preserve state; report failure] F -->|Success or permanent rejection| H{Snapshot still current?} H -->|No| I[Discard stale result] H -->|Yes| J[Persist proposed state] J -->|Success| K[Install access token] J -->|Permanent rejection| L[Report rejection]Compatibility caveat: every refresh retries a permanently rejected bridge configuration, even if its credentials are unchanged. This allows corrected configuration to recover without clearing the manifest. A separate credential-fingerprint follow-up will distinguish changed credentials from repeated attempts with the rejected pair.
Tests exercise provider precedence, token rotation, transient and permanent failures, and logout/reauthorization during an in-flight refresh. #450 documents the architecture; #451 handles separate playback authorization.