Skip to content

Make the oauth object optional - #29

Merged
frostevent merged 2 commits into
mainfrom
jeremie/optional-oauth
Sep 29, 2026
Merged

frostevent merged 2 commits into
mainfrom
jeremie/optional-oauth

Conversation

@frostevent

Copy link
Copy Markdown
Collaborator

Summary

Follow-up to #27, which only made token_endpoint optional. The intended behavior is:

  • The whole oauth object is optional on X401Payload and on the buildPayload input. buildPayload omits the key when it is not supplied.
  • When oauth is present, token_endpoint is required (a string). OAuthMetadata.token_endpoint is back to string.
  • parseX401Payload skips the oauth check when the key is absent, and rejects a non-object oauth or an oauth without a string token_endpoint.

Tests updated: a round-trip without oauth, rejection of oauth without token_endpoint, rejection of a non-string token_endpoint, rejection of a non-object oauth. spec/conformance.md and the README reflect the new behavior.

The spec (v0.2.0) still marks oauth as REQUIRED; that is being corrected. The pinned spec artifacts under spec/fixtures and spec/normative-ledger.json are verbatim copies of the published spec and are left untouched until the next sync.

Test plan

  • yarn check-all passes (format, lint, typecheck, 39 tests, publint).

🤖 Generated with Claude Code

Jeremie Charrier and others added 2 commits September 29, 2026 14:01
The spec marks oauth as REQUIRED, but that is being corrected. The
whole oauth object is now optional in the payload type, the parser, and
buildPayload. When oauth is present, token_endpoint is required again.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
@frostevent
frostevent merged commit ec0776f into main Sep 29, 2026
8 checks passed
@frostevent
frostevent deleted the jeremie/optional-oauth branch September 29, 2026 12:06
@frostevent frostevent mentioned this pull request Sep 29, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant