From 6436f0b82f72e0ab680422995b636e538934db13 Mon Sep 17 00:00:00 2001 From: Trezy Date: Fri, 8 May 2026 09:51:10 -0500 Subject: [PATCH] docs: explain how to access approved session scopes Signed-off-by: Trezy --- packages/docs/docs/sdk/oauth-client-browser.md | 17 +++++++++++++++++ packages/docs/docs/sdk/oauth-client.md | 17 +++++++++++++++++ packages/oauth-client/README.md | 15 +++++++++++++++ 3 files changed, 49 insertions(+) diff --git a/packages/docs/docs/sdk/oauth-client-browser.md b/packages/docs/docs/sdk/oauth-client-browser.md index c21b21e..f684e83 100644 --- a/packages/docs/docs/sdk/oauth-client-browser.md +++ b/packages/docs/docs/sdk/oauth-client-browser.md @@ -148,6 +148,23 @@ if (params) { } ``` +## Checking approved scopes + +After sign in or session restoration, you can check which scopes were approved: + +```typescript +console.log(session.scopes); +// ["atproto", "transition:generic"] +``` + +To fetch the latest scopes from the server: + +```typescript +const info = await client.getSession("did:plc:abc123"); +console.log(info.scopes); +// ["atproto", "transition:generic"] +``` + ## Authenticated requests The session's `fetchHandler` attaches DPoP proof headers automatically: diff --git a/packages/docs/docs/sdk/oauth-client.md b/packages/docs/docs/sdk/oauth-client.md index b73d034..4e90da3 100644 --- a/packages/docs/docs/sdk/oauth-client.md +++ b/packages/docs/docs/sdk/oauth-client.md @@ -59,6 +59,23 @@ const session = await client.registerSession({ The returned `HappyViewSession` is ready to make authenticated requests. The session data is also persisted to the `StorageAdapter` for later restoration. +The response includes the scopes that were approved by the authorization server, available on the session: + +```typescript +console.log(session.scopes); +// ["atproto", "transition:generic"] +``` + +## Retrieving session info + +To fetch the current session's approved scopes from the server (e.g., after restoring from storage): + +```typescript +const info = await client.getSession("did:plc:abc123"); +console.log(info.scopes); +// ["atproto", "transition:generic"] +``` + ## Making authenticated requests `HappyViewSession.fetchHandler` works like `fetch` but automatically attaches DPoP proof, authorization, and client key headers: diff --git a/packages/oauth-client/README.md b/packages/oauth-client/README.md index 3f50d24..bcb66e6 100644 --- a/packages/oauth-client/README.md +++ b/packages/oauth-client/README.md @@ -52,6 +52,21 @@ const session = await client.registerSession({ }); ``` +The returned session includes the approved scopes: + +```typescript +console.log(session.scopes); // ["atproto", "transition:generic"] +``` + +### Retrieving Session Info + +Fetch the current session's approved scopes from the server: + +```typescript +const info = await client.getSession("did:plc:abc123"); +console.log(info.scopes); // ["atproto", "transition:generic"] +``` + ### Making Authenticated Requests The returned `HappyViewSession` provides a `fetchHandler` that automatically attaches DPoP proof headers: -- 2.51.2