feat: add best effort attempt to revoke oauth access token in external auth provider (#19775)

Solves #15575
Adds OAuth access token revocation when unlinking external auth
provider. Due to revocation not being consistently implemented by
providers this is only best effort attempt. Unsuccessful revocation
won't influence link removal.
This commit is contained in:
Paweł Banaszewski
2025-09-19 16:27:02 +02:00
committed by GitHub
parent 0601cc8fa6
commit 439b041780
24 changed files with 629 additions and 69 deletions
+1
View File
@@ -259,6 +259,7 @@ curl -X GET http://coder-server:8080/api/v2/deployment/config \
"mcp_url": "string",
"no_refresh": true,
"regex": "string",
"revoke_url": "string",
"scopes": [
"string"
],
+16 -3
View File
@@ -80,6 +80,7 @@ curl -X GET http://coder-server:8080/api/v2/external-auth/{externalauth} \
"id": 0
}
],
"supports_revocation": true,
"user": {
"avatar_url": "string",
"id": 0,
@@ -105,6 +106,7 @@ To perform this operation, you must be authenticated. [Learn more](authenticatio
```shell
# Example request using curl
curl -X DELETE http://coder-server:8080/api/v2/external-auth/{externalauth} \
-H 'Accept: application/json' \
-H 'Coder-Session-Token: API_KEY'
```
@@ -116,11 +118,22 @@ curl -X DELETE http://coder-server:8080/api/v2/external-auth/{externalauth} \
|----------------|------|----------------|----------|-----------------|
| `externalauth` | path | string(string) | true | Git Provider ID |
### Example responses
> 200 Response
```json
{
"token_revocation_error": "string",
"token_revoked": true
}
```
### Responses
| Status | Meaning | Description | Schema |
|--------|---------------------------------------------------------|-------------|--------|
| 200 | [OK](https://tools.ietf.org/html/rfc7231#section-6.3.1) | OK | |
| Status | Meaning | Description | Schema |
|--------|---------------------------------------------------------|-------------|----------------------------------------------------------------------------------------------|
| 200 | [OK](https://tools.ietf.org/html/rfc7231#section-6.3.1) | OK | [codersdk.DeleteExternalAuthByIDResponse](schemas.md#codersdkdeleteexternalauthbyidresponse) |
To perform this operation, you must be authenticated. [Learn more](authentication.md).
+32 -9
View File
@@ -2196,6 +2196,22 @@ CreateWorkspaceRequest provides options for creating a new workspace. Only one o
| `allow_path_app_sharing` | boolean | false | | |
| `allow_path_app_site_owner_access` | boolean | false | | |
## codersdk.DeleteExternalAuthByIDResponse
```json
{
"token_revocation_error": "string",
"token_revoked": true
}
```
### Properties
| Name | Type | Required | Restrictions | Description |
|--------------------------|---------|----------|--------------|--------------------------------------------------------------------------------|
| `token_revocation_error` | string | false | | |
| `token_revoked` | boolean | false | | Token revoked set to true if token revocation was attempted and was successful |
## codersdk.DeleteWebpushSubscription
```json
@@ -2363,6 +2379,7 @@ CreateWorkspaceRequest provides options for creating a new workspace. Only one o
"mcp_url": "string",
"no_refresh": true,
"regex": "string",
"revoke_url": "string",
"scopes": [
"string"
],
@@ -2867,6 +2884,7 @@ CreateWorkspaceRequest provides options for creating a new workspace. Only one o
"mcp_url": "string",
"no_refresh": true,
"regex": "string",
"revoke_url": "string",
"scopes": [
"string"
],
@@ -3509,6 +3527,7 @@ CreateWorkspaceRequest provides options for creating a new workspace. Only one o
"id": 0
}
],
"supports_revocation": true,
"user": {
"avatar_url": "string",
"id": 0,
@@ -3521,15 +3540,16 @@ CreateWorkspaceRequest provides options for creating a new workspace. Only one o
### Properties
| Name | Type | Required | Restrictions | Description |
|-------------------|---------------------------------------------------------------------------------------|----------|--------------|-------------------------------------------------------------------------|
| `app_install_url` | string | false | | App install URL is the URL to install the app. |
| `app_installable` | boolean | false | | App installable is true if the request for app installs was successful. |
| `authenticated` | boolean | false | | |
| `device` | boolean | false | | |
| `display_name` | string | false | | |
| `installations` | array of [codersdk.ExternalAuthAppInstallation](#codersdkexternalauthappinstallation) | false | | Installations are the installations that the user has access to. |
| `user` | [codersdk.ExternalAuthUser](#codersdkexternalauthuser) | false | | User is the user that authenticated with the provider. |
| Name | Type | Required | Restrictions | Description |
|-----------------------|---------------------------------------------------------------------------------------|----------|--------------|-------------------------------------------------------------------------|
| `app_install_url` | string | false | | App install URL is the URL to install the app. |
| `app_installable` | boolean | false | | App installable is true if the request for app installs was successful. |
| `authenticated` | boolean | false | | |
| `device` | boolean | false | | |
| `display_name` | string | false | | |
| `installations` | array of [codersdk.ExternalAuthAppInstallation](#codersdkexternalauthappinstallation) | false | | Installations are the installations that the user has access to. |
| `supports_revocation` | boolean | false | | |
| `user` | [codersdk.ExternalAuthUser](#codersdkexternalauthuser) | false | | User is the user that authenticated with the provider. |
## codersdk.ExternalAuthAppInstallation
@@ -3573,6 +3593,7 @@ CreateWorkspaceRequest provides options for creating a new workspace. Only one o
"mcp_url": "string",
"no_refresh": true,
"regex": "string",
"revoke_url": "string",
"scopes": [
"string"
],
@@ -3601,6 +3622,7 @@ CreateWorkspaceRequest provides options for creating a new workspace. Only one o
| `no_refresh` | boolean | false | | |
|`regex`|string|false||Regex allows API requesters to match an auth config by a string (e.g. coder.com) instead of by it's type.
Git clone makes use of this by parsing the URL from: 'Username for "https://github.com":' And sending it to the Coder server to match against the Regex.|
|`revoke_url`|string|false|||
|`scopes`|array of string|false|||
|`token_url`|string|false|||
|`type`|string|false||Type is the type of external auth config.|
@@ -12868,6 +12890,7 @@ None
"mcp_url": "string",
"no_refresh": true,
"regex": "string",
"revoke_url": "string",
"scopes": [
"string"
],