refactor: add RFC-compliant enum types and use SDK as source of truth (#21468)

Add comprehensive OAuth2 enum types to codersdk following RFC specifications:
- OAuth2ProviderGrantType (RFC 6749)
- OAuth2ProviderResponseType (RFC 6749)
- OAuth2TokenEndpointAuthMethod (RFC 7591)
- OAuth2PKCECodeChallengeMethod (RFC 7636)
- OAuth2TokenType (RFC 6749, RFC 9449)
- OAuth2RevocationTokenTypeHint (RFC 7009)
- OAuth2ErrorCode (RFC 6749, RFC 7009, RFC 8707)

Add OAuth2TokenRequest, OAuth2TokenResponse, OAuth2TokenRevocationRequest,
and OAuth2Error structs to the SDK. Update OAuth2ClientRegistrationRequest,
OAuth2ClientRegistrationResponse, OAuth2ClientConfiguration, and
OAuth2AuthorizationServerMetadata to use typed enums instead of raw strings.

This makes codersdk the single source of truth for OAuth2 types, eliminating
duplication between SDK and server-side structs.

Closes #21476
This commit is contained in:
Ehab Younes
2026-01-15 12:41:28 +03:00
committed by GitHub
parent 7c2479ce92
commit 6683d807ac
25 changed files with 1091 additions and 532 deletions
+30 -34
View File
@@ -20,15 +20,15 @@ curl -X GET http://coder-server:8080/api/v2/.well-known/oauth-authorization-serv
{
"authorization_endpoint": "string",
"code_challenge_methods_supported": [
"string"
"S256"
],
"grant_types_supported": [
"string"
"authorization_code"
],
"issuer": "string",
"registration_endpoint": "string",
"response_types_supported": [
"string"
"code"
],
"revocation_endpoint": "string",
"scopes_supported": [
@@ -36,7 +36,7 @@ curl -X GET http://coder-server:8080/api/v2/.well-known/oauth-authorization-serv
],
"token_endpoint": "string",
"token_endpoint_auth_methods_supported": [
"string"
"client_secret_basic"
]
}
```
@@ -1265,9 +1265,9 @@ curl -X GET http://coder-server:8080/api/v2/oauth2/authorize?client_id=string&st
#### Enumerated Values
| Parameter | Value(s) |
|-----------------|----------|
| `response_type` | `code` |
| Parameter | Value(s) |
|-----------------|-----------------|
| `response_type` | `code`, `token` |
### Responses
@@ -1301,9 +1301,9 @@ curl -X POST http://coder-server:8080/api/v2/oauth2/authorize?client_id=string&s
#### Enumerated Values
| Parameter | Value(s) |
|-----------------|----------|
| `response_type` | `code` |
| Parameter | Value(s) |
|-----------------|-----------------|
| `response_type` | `code`, `token` |
### Responses
@@ -1346,7 +1346,7 @@ curl -X GET http://coder-server:8080/api/v2/oauth2/clients/{client_id} \
"string"
],
"grant_types": [
"string"
"authorization_code"
],
"jwks": {},
"jwks_uri": "string",
@@ -1355,17 +1355,15 @@ curl -X GET http://coder-server:8080/api/v2/oauth2/clients/{client_id} \
"redirect_uris": [
"string"
],
"registration_access_token": [
0
],
"registration_access_token": "string",
"registration_client_uri": "string",
"response_types": [
"string"
"code"
],
"scope": "string",
"software_id": "string",
"software_version": "string",
"token_endpoint_auth_method": "string",
"token_endpoint_auth_method": "client_secret_basic",
"tos_uri": "string"
}
```
@@ -1399,7 +1397,7 @@ curl -X PUT http://coder-server:8080/api/v2/oauth2/clients/{client_id} \
"string"
],
"grant_types": [
"string"
"authorization_code"
],
"jwks": {},
"jwks_uri": "string",
@@ -1409,13 +1407,13 @@ curl -X PUT http://coder-server:8080/api/v2/oauth2/clients/{client_id} \
"string"
],
"response_types": [
"string"
"code"
],
"scope": "string",
"software_id": "string",
"software_statement": "string",
"software_version": "string",
"token_endpoint_auth_method": "string",
"token_endpoint_auth_method": "client_secret_basic",
"tos_uri": "string"
}
```
@@ -1442,7 +1440,7 @@ curl -X PUT http://coder-server:8080/api/v2/oauth2/clients/{client_id} \
"string"
],
"grant_types": [
"string"
"authorization_code"
],
"jwks": {},
"jwks_uri": "string",
@@ -1451,17 +1449,15 @@ curl -X PUT http://coder-server:8080/api/v2/oauth2/clients/{client_id} \
"redirect_uris": [
"string"
],
"registration_access_token": [
0
],
"registration_access_token": "string",
"registration_client_uri": "string",
"response_types": [
"string"
"code"
],
"scope": "string",
"software_id": "string",
"software_version": "string",
"token_endpoint_auth_method": "string",
"token_endpoint_auth_method": "client_secret_basic",
"tos_uri": "string"
}
```
@@ -1519,7 +1515,7 @@ curl -X POST http://coder-server:8080/api/v2/oauth2/register \
"string"
],
"grant_types": [
"string"
"authorization_code"
],
"jwks": {},
"jwks_uri": "string",
@@ -1529,13 +1525,13 @@ curl -X POST http://coder-server:8080/api/v2/oauth2/register \
"string"
],
"response_types": [
"string"
"code"
],
"scope": "string",
"software_id": "string",
"software_statement": "string",
"software_version": "string",
"token_endpoint_auth_method": "string",
"token_endpoint_auth_method": "client_secret_basic",
"tos_uri": "string"
}
```
@@ -1562,7 +1558,7 @@ curl -X POST http://coder-server:8080/api/v2/oauth2/register \
"string"
],
"grant_types": [
"string"
"authorization_code"
],
"jwks": {},
"jwks_uri": "string",
@@ -1574,12 +1570,12 @@ curl -X POST http://coder-server:8080/api/v2/oauth2/register \
"registration_access_token": "string",
"registration_client_uri": "string",
"response_types": [
"string"
"code"
],
"scope": "string",
"software_id": "string",
"software_version": "string",
"token_endpoint_auth_method": "string",
"token_endpoint_auth_method": "client_secret_basic",
"tos_uri": "string"
}
```
@@ -1662,9 +1658,9 @@ grant_type: authorization_code
#### Enumerated Values
| Parameter | Value(s) |
|----------------|---------------------------------------|
| `» grant_type` | `authorization_code`, `refresh_token` |
| Parameter | Value(s) |
|----------------|-------------------------------------------------------------------------------------|
| `» grant_type` | `authorization_code`, `client_credentials`, `implicit`, `password`, `refresh_token` |
### Example responses
+145 -91
View File
@@ -5188,15 +5188,15 @@ Only certain features set these fields: - FeatureManagedAgentLimit|
{
"authorization_endpoint": "string",
"code_challenge_methods_supported": [
"string"
"S256"
],
"grant_types_supported": [
"string"
"authorization_code"
],
"issuer": "string",
"registration_endpoint": "string",
"response_types_supported": [
"string"
"code"
],
"revocation_endpoint": "string",
"scopes_supported": [
@@ -5204,25 +5204,25 @@ Only certain features set these fields: - FeatureManagedAgentLimit|
],
"token_endpoint": "string",
"token_endpoint_auth_methods_supported": [
"string"
"client_secret_basic"
]
}
```
### Properties
| Name | Type | Required | Restrictions | Description |
|-----------------------------------------|-----------------|----------|--------------|-------------|
| `authorization_endpoint` | string | false | | |
| `code_challenge_methods_supported` | array of string | false | | |
| `grant_types_supported` | array of string | false | | |
| `issuer` | string | false | | |
| `registration_endpoint` | string | false | | |
| `response_types_supported` | array of string | false | | |
| `revocation_endpoint` | string | false | | |
| `scopes_supported` | array of string | false | | |
| `token_endpoint` | string | false | | |
| `token_endpoint_auth_methods_supported` | array of string | false | | |
| Name | Type | Required | Restrictions | Description |
|-----------------------------------------|-------------------------------------------------------------------------------------------|----------|--------------|-------------|
| `authorization_endpoint` | string | false | | |
| `code_challenge_methods_supported` | array of [codersdk.OAuth2PKCECodeChallengeMethod](#codersdkoauth2pkcecodechallengemethod) | false | | |
| `grant_types_supported` | array of [codersdk.OAuth2ProviderGrantType](#codersdkoauth2providergranttype) | false | | |
| `issuer` | string | false | | |
| `registration_endpoint` | string | false | | |
| `response_types_supported` | array of [codersdk.OAuth2ProviderResponseType](#codersdkoauth2providerresponsetype) | false | | |
| `revocation_endpoint` | string | false | | |
| `scopes_supported` | array of string | false | | |
| `token_endpoint` | string | false | | |
| `token_endpoint_auth_methods_supported` | array of [codersdk.OAuth2TokenEndpointAuthMethod](#codersdkoauth2tokenendpointauthmethod) | false | | |
## codersdk.OAuth2ClientConfiguration
@@ -5237,7 +5237,7 @@ Only certain features set these fields: - FeatureManagedAgentLimit|
"string"
],
"grant_types": [
"string"
"authorization_code"
],
"jwks": {},
"jwks_uri": "string",
@@ -5246,45 +5246,43 @@ Only certain features set these fields: - FeatureManagedAgentLimit|
"redirect_uris": [
"string"
],
"registration_access_token": [
0
],
"registration_access_token": "string",
"registration_client_uri": "string",
"response_types": [
"string"
"code"
],
"scope": "string",
"software_id": "string",
"software_version": "string",
"token_endpoint_auth_method": "string",
"token_endpoint_auth_method": "client_secret_basic",
"tos_uri": "string"
}
```
### Properties
| Name | Type | Required | Restrictions | Description |
|------------------------------|------------------|----------|--------------|-------------|
| `client_id` | string | false | | |
| `client_id_issued_at` | integer | false | | |
| `client_name` | string | false | | |
| `client_secret_expires_at` | integer | false | | |
| `client_uri` | string | false | | |
| `contacts` | array of string | false | | |
| `grant_types` | array of string | false | | |
| `jwks` | object | false | | |
| `jwks_uri` | string | false | | |
| `logo_uri` | string | false | | |
| `policy_uri` | string | false | | |
| `redirect_uris` | array of string | false | | |
| `registration_access_token` | array of integer | false | | |
| `registration_client_uri` | string | false | | |
| `response_types` | array of string | false | | |
| `scope` | string | false | | |
| `software_id` | string | false | | |
| `software_version` | string | false | | |
| `token_endpoint_auth_method` | string | false | | |
| `tos_uri` | string | false | | |
| Name | Type | Required | Restrictions | Description |
|------------------------------|-------------------------------------------------------------------------------------|----------|--------------|-------------|
| `client_id` | string | false | | |
| `client_id_issued_at` | integer | false | | |
| `client_name` | string | false | | |
| `client_secret_expires_at` | integer | false | | |
| `client_uri` | string | false | | |
| `contacts` | array of string | false | | |
| `grant_types` | array of [codersdk.OAuth2ProviderGrantType](#codersdkoauth2providergranttype) | false | | |
| `jwks` | object | false | | |
| `jwks_uri` | string | false | | |
| `logo_uri` | string | false | | |
| `policy_uri` | string | false | | |
| `redirect_uris` | array of string | false | | |
| `registration_access_token` | string | false | | |
| `registration_client_uri` | string | false | | |
| `response_types` | array of [codersdk.OAuth2ProviderResponseType](#codersdkoauth2providerresponsetype) | false | | |
| `scope` | string | false | | |
| `software_id` | string | false | | |
| `software_version` | string | false | | |
| `token_endpoint_auth_method` | [codersdk.OAuth2TokenEndpointAuthMethod](#codersdkoauth2tokenendpointauthmethod) | false | | |
| `tos_uri` | string | false | | |
## codersdk.OAuth2ClientRegistrationRequest
@@ -5296,7 +5294,7 @@ Only certain features set these fields: - FeatureManagedAgentLimit|
"string"
],
"grant_types": [
"string"
"authorization_code"
],
"jwks": {},
"jwks_uri": "string",
@@ -5306,37 +5304,37 @@ Only certain features set these fields: - FeatureManagedAgentLimit|
"string"
],
"response_types": [
"string"
"code"
],
"scope": "string",
"software_id": "string",
"software_statement": "string",
"software_version": "string",
"token_endpoint_auth_method": "string",
"token_endpoint_auth_method": "client_secret_basic",
"tos_uri": "string"
}
```
### Properties
| Name | Type | Required | Restrictions | Description |
|------------------------------|-----------------|----------|--------------|-------------|
| `client_name` | string | false | | |
| `client_uri` | string | false | | |
| `contacts` | array of string | false | | |
| `grant_types` | array of string | false | | |
| `jwks` | object | false | | |
| `jwks_uri` | string | false | | |
| `logo_uri` | string | false | | |
| `policy_uri` | string | false | | |
| `redirect_uris` | array of string | false | | |
| `response_types` | array of string | false | | |
| `scope` | string | false | | |
| `software_id` | string | false | | |
| `software_statement` | string | false | | |
| `software_version` | string | false | | |
| `token_endpoint_auth_method` | string | false | | |
| `tos_uri` | string | false | | |
| Name | Type | Required | Restrictions | Description |
|------------------------------|-------------------------------------------------------------------------------------|----------|--------------|-------------|
| `client_name` | string | false | | |
| `client_uri` | string | false | | |
| `contacts` | array of string | false | | |
| `grant_types` | array of [codersdk.OAuth2ProviderGrantType](#codersdkoauth2providergranttype) | false | | |
| `jwks` | object | false | | |
| `jwks_uri` | string | false | | |
| `logo_uri` | string | false | | |
| `policy_uri` | string | false | | |
| `redirect_uris` | array of string | false | | |
| `response_types` | array of [codersdk.OAuth2ProviderResponseType](#codersdkoauth2providerresponsetype) | false | | |
| `scope` | string | false | | |
| `software_id` | string | false | | |
| `software_statement` | string | false | | |
| `software_version` | string | false | | |
| `token_endpoint_auth_method` | [codersdk.OAuth2TokenEndpointAuthMethod](#codersdkoauth2tokenendpointauthmethod) | false | | |
| `tos_uri` | string | false | | |
## codersdk.OAuth2ClientRegistrationResponse
@@ -5352,7 +5350,7 @@ Only certain features set these fields: - FeatureManagedAgentLimit|
"string"
],
"grant_types": [
"string"
"authorization_code"
],
"jwks": {},
"jwks_uri": "string",
@@ -5364,41 +5362,41 @@ Only certain features set these fields: - FeatureManagedAgentLimit|
"registration_access_token": "string",
"registration_client_uri": "string",
"response_types": [
"string"
"code"
],
"scope": "string",
"software_id": "string",
"software_version": "string",
"token_endpoint_auth_method": "string",
"token_endpoint_auth_method": "client_secret_basic",
"tos_uri": "string"
}
```
### Properties
| Name | Type | Required | Restrictions | Description |
|------------------------------|-----------------|----------|--------------|-------------|
| `client_id` | string | false | | |
| `client_id_issued_at` | integer | false | | |
| `client_name` | string | false | | |
| `client_secret` | string | false | | |
| `client_secret_expires_at` | integer | false | | |
| `client_uri` | string | false | | |
| `contacts` | array of string | false | | |
| `grant_types` | array of string | false | | |
| `jwks` | object | false | | |
| `jwks_uri` | string | false | | |
| `logo_uri` | string | false | | |
| `policy_uri` | string | false | | |
| `redirect_uris` | array of string | false | | |
| `registration_access_token` | string | false | | |
| `registration_client_uri` | string | false | | |
| `response_types` | array of string | false | | |
| `scope` | string | false | | |
| `software_id` | string | false | | |
| `software_version` | string | false | | |
| `token_endpoint_auth_method` | string | false | | |
| `tos_uri` | string | false | | |
| Name | Type | Required | Restrictions | Description |
|------------------------------|-------------------------------------------------------------------------------------|----------|--------------|-------------|
| `client_id` | string | false | | |
| `client_id_issued_at` | integer | false | | |
| `client_name` | string | false | | |
| `client_secret` | string | false | | |
| `client_secret_expires_at` | integer | false | | |
| `client_uri` | string | false | | |
| `contacts` | array of string | false | | |
| `grant_types` | array of [codersdk.OAuth2ProviderGrantType](#codersdkoauth2providergranttype) | false | | |
| `jwks` | object | false | | |
| `jwks_uri` | string | false | | |
| `logo_uri` | string | false | | |
| `policy_uri` | string | false | | |
| `redirect_uris` | array of string | false | | |
| `registration_access_token` | string | false | | |
| `registration_client_uri` | string | false | | |
| `response_types` | array of [codersdk.OAuth2ProviderResponseType](#codersdkoauth2providerresponsetype) | false | | |
| `scope` | string | false | | |
| `software_id` | string | false | | |
| `software_version` | string | false | | |
| `token_endpoint_auth_method` | [codersdk.OAuth2TokenEndpointAuthMethod](#codersdkoauth2tokenendpointauthmethod) | false | | |
| `tos_uri` | string | false | | |
## codersdk.OAuth2Config
@@ -5462,6 +5460,20 @@ Only certain features set these fields: - FeatureManagedAgentLimit|
| `device_flow` | boolean | false | | |
| `enterprise_base_url` | string | false | | |
## codersdk.OAuth2PKCECodeChallengeMethod
```json
"S256"
```
### Properties
#### Enumerated Values
| Value(s) |
|-----------------|
| `S256`, `plain` |
## codersdk.OAuth2ProtectedResourceMetadata
```json
@@ -5549,6 +5561,48 @@ Only certain features set these fields: - FeatureManagedAgentLimit|
| `client_secret_full` | string | false | | |
| `id` | string | false | | |
## codersdk.OAuth2ProviderGrantType
```json
"authorization_code"
```
### Properties
#### Enumerated Values
| Value(s) |
|-------------------------------------------------------------------------------------|
| `authorization_code`, `client_credentials`, `implicit`, `password`, `refresh_token` |
## codersdk.OAuth2ProviderResponseType
```json
"code"
```
### Properties
#### Enumerated Values
| Value(s) |
|-----------------|
| `code`, `token` |
## codersdk.OAuth2TokenEndpointAuthMethod
```json
"client_secret_basic"
```
### Properties
#### Enumerated Values
| Value(s) |
|-----------------------------------------------------|
| `client_secret_basic`, `client_secret_post`, `none` |
## codersdk.OAuthConversionResponse
```json