diff --git a/internal/api/routes/oauth.go b/internal/api/routes/oauth.go index 0a51266..7341978 100644 --- a/internal/api/routes/oauth.go +++ b/internal/api/routes/oauth.go @@ -27,7 +27,8 @@ func RegisterOAuthRoutes(r chi.Router, handler *oauth.OAuthHandler, allowedOrigi logoutLimiter := middleware.NewRateLimiter(10, 1*time.Minute) // OAuth metadata endpoints - public, no extra rate limiting (use global limit) - r.Get("/oauth/client-metadata.json", handler.HandleClientMetadata) + // Serve at root /oauth-client-metadata.json so OAuth screens show clean brand domain + r.Get("/oauth-client-metadata.json", handler.HandleClientMetadata) r.Get("/.well-known/oauth-protected-resource", handler.HandleProtectedResourceMetadata) // OAuth flow endpoints - stricter rate limiting for authentication attempts diff --git a/internal/atproto/oauth/client.go b/internal/atproto/oauth/client.go index 2153b06..540e6d9 100644 --- a/internal/atproto/oauth/client.go +++ b/internal/atproto/oauth/client.go @@ -90,7 +90,7 @@ func NewOAuthClient(config *OAuthConfig, store oauth.ClientAuthStore) (*OAuthCli } else { // Production mode: public OAuth client with HTTPS // client_id must be the URL of the client metadata document per atproto OAuth spec - clientID := config.PublicURL + "/oauth/client-metadata.json" + clientID := config.PublicURL + "/oauth-client-metadata.json" callbackURL := config.PublicURL + "/oauth/callback" clientConfig = oauth.NewPublicConfig(clientID, callbackURL, config.Scopes) } diff --git a/internal/atproto/oauth/handlers.go b/internal/atproto/oauth/handlers.go index b59ce3b..1fa5443 100644 --- a/internal/atproto/oauth/handlers.go +++ b/internal/atproto/oauth/handlers.go @@ -210,7 +210,7 @@ func NewOAuthHandler(client *OAuthClient, store oauth.ClientAuthStore, opts ...O } // HandleClientMetadata serves the OAuth client metadata document -// GET /oauth/client-metadata.json +// GET /oauth-client-metadata.json func (h *OAuthHandler) HandleClientMetadata(w http.ResponseWriter, r *http.Request) { metadata := h.client.ClientMetadata() diff --git a/internal/atproto/oauth/handlers_test.go b/internal/atproto/oauth/handlers_test.go index 0ef59f6..674f114 100644 --- a/internal/atproto/oauth/handlers_test.go +++ b/internal/atproto/oauth/handlers_test.go @@ -50,7 +50,7 @@ func TestHandleClientMetadata(t *testing.T) { // Validate metadata // Per atproto OAuth spec, client_id for public clients is the client metadata URL - assert.Equal(t, "https://coves.social/oauth/client-metadata.json", metadata.ClientID) + assert.Equal(t, "https://coves.social/oauth-client-metadata.json", metadata.ClientID) assert.Contains(t, metadata.RedirectURIs, "https://coves.social/oauth/callback") assert.Contains(t, metadata.GrantTypes, "authorization_code") assert.Contains(t, metadata.GrantTypes, "refresh_token")