Something went wrong. Try again.
[READ-ONLY] Mirror of https://github.com/openstatusHQ/openstatus. ๐ซ Status page with uptime monitoring & API monitoring as code ๐ซ openstatus.dev
bun drizzle-orm monitoring monitoring-as-code nextjs observability on-call open-source shadcn-ui status-page statuspage synthetic-monitoring tinybird turso uptime uptime-checker uptime-monitor
Something went wrong. Try again.
2.1 kB ยท 67 lines
TypeScript
1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768import { db as defaultDb } from "@openstatus/db";import { oauthClient } from "@openstatus/db/src/schema";
import type { DB } from "../context";import { InternalServiceError } from "../errors";import { GRANT_TYPES, RESPONSE_TYPES } from "./constants";import { randomHex } from "./crypto";import { OAuthError } from "./errors";import { isAllowedRedirectUri } from "./redirect-allowlist";import { RegisterClientInput } from "./schemas";
export type RegisteredClient = { client_id: string; client_id_issued_at: number; client_name: string; redirect_uris: string[]; token_endpoint_auth_method: "none"; grant_types: string[]; response_types: string[];};
/** RFC 7591 dynamic registration. Public clients only; every redirect URI must pass the allowlist. */export async function registerClient(args: { input: RegisterClientInput; db?: DB;}): Promise<RegisteredClient> { const parsed = RegisterClientInput.safeParse(args.input); if (!parsed.success) { throw new OAuthError( "invalid_client_metadata", parsed.error.issues.map((i) => i.message).join("; "), ); } const input = parsed.data; const db = args.db ?? defaultDb;
const redirectUris = Array.from(new Set(input.redirect_uris)); const rejected = redirectUris.filter((uri) => !isAllowedRedirectUri(uri)); if (rejected.length > 0) { throw new OAuthError( "invalid_redirect_uri", `redirect_uris must target an allowlisted host, a loopback address or a supported app scheme. Rejected: ${rejected.join(", ")}`, ); }
const [row] = await db .insert(oauthClient) .values({ clientId: randomHex(16), name: input.client_name ?? "MCP Client", redirectUris, }) .returning(); if (!row) throw new InternalServiceError("Failed to register client");
return { client_id: row.clientId, client_id_issued_at: Math.floor( (row.createdAt ?? new Date()).getTime() / 1000, ), client_name: row.name, redirect_uris: row.redirectUris, token_endpoint_auth_method: "none", grant_types: [...GRANT_TYPES], response_types: [...RESPONSE_TYPES], };}