From 3ee9ae0ec713032b1ce3272f9104af147a698486 Mon Sep 17 00:00:00 2001 From: Seongmin Lee Date: Thu, 3 Sep 2026 23:04:50 +0900 Subject: [PATCH] web: split oauth scope string into an array Signed-off-by: Seongmin Lee --- web/src/lib/api/accept.test.ts | 2 +- web/src/lib/auth.svelte.ts | 2 +- .../notifications/NotificationItem.test.ts | 2 +- web/src/lib/oauth-client-metadata.json | 12 --- web/src/lib/oauth-client-metadata.ts | 86 +++++++++++++++++++ .../oauth-client-metadata.json/+server.ts | 2 +- web/vite.config.ts | 2 +- 7 files changed, 91 insertions(+), 17 deletions(-) delete mode 100644 web/src/lib/oauth-client-metadata.json create mode 100644 web/src/lib/oauth-client-metadata.ts diff --git a/web/src/lib/api/accept.test.ts b/web/src/lib/api/accept.test.ts index eed4daa84..9d66164ad 100644 --- a/web/src/lib/api/accept.test.ts +++ b/web/src/lib/api/accept.test.ts @@ -1,7 +1,7 @@ import { describe, expect, it, vi } from "vitest"; import type { OAuthUserAgent } from "@atcute/oauth-browser-client"; import { ClientResponseError } from "@atcute/client"; -import oauthMetadata from "$lib/oauth-client-metadata.json"; +import oauthMetadata from "$lib/oauth-client-metadata"; import { missingPermissions } from "$lib/auth/scopes"; import type { DidRkey, NotificationOffer } from "$lib/components/notifications/types"; import type * as Accept from "$lib/api/accept"; diff --git a/web/src/lib/auth.svelte.ts b/web/src/lib/auth.svelte.ts index b1c721a02..79df96a2d 100644 --- a/web/src/lib/auth.svelte.ts +++ b/web/src/lib/auth.svelte.ts @@ -20,7 +20,7 @@ import { } from "@atcute/oauth-browser-client"; import { getContext } from "svelte"; import { SvelteMap, SvelteURL, SvelteURLSearchParams } from "svelte/reactivity"; -import oauthMetadata from "$lib/oauth-client-metadata.json"; +import oauthMetadata from "$lib/oauth-client-metadata"; import { type AuthAccount, clearActive, diff --git a/web/src/lib/components/notifications/NotificationItem.test.ts b/web/src/lib/components/notifications/NotificationItem.test.ts index 82bce9deb..463258ab4 100644 --- a/web/src/lib/components/notifications/NotificationItem.test.ts +++ b/web/src/lib/components/notifications/NotificationItem.test.ts @@ -5,7 +5,7 @@ import NotificationItem from "$lib/components/notifications/NotificationItem.sve import { notifications } from "$lib/components/notifications/mock"; import type { NotificationSummary } from "$lib/components/notifications/types"; import { AUTH_KEY, type Auth } from "$lib/auth.svelte"; -import oauthMetadata from "$lib/oauth-client-metadata.json"; +import oauthMetadata from "$lib/oauth-client-metadata"; const rowOf = (type: NotificationSummary["type"]): NotificationSummary => { const found = notifications.find((notification) => notification.type === type); diff --git a/web/src/lib/oauth-client-metadata.json b/web/src/lib/oauth-client-metadata.json deleted file mode 100644 index dea7b9986..000000000 --- a/web/src/lib/oauth-client-metadata.json +++ /dev/null @@ -1,12 +0,0 @@ -{ - "client_id": "https://tangled.org/oauth-client-metadata.json", - "client_name": "Tangled", - "client_uri": "https://tangled.org", - "redirect_uris": ["https://tangled.org/oauth/callback"], - "scope": "atproto repo:sh.tangled.actor.profile repo:org.tangled.feed.subscription repo:sh.tangled.feed.comment repo:sh.tangled.feed.reaction repo:sh.tangled.feed.star repo:sh.tangled.graph.follow repo:sh.tangled.graph.vouch repo:sh.tangled.knot repo:sh.tangled.knot.member repo:sh.tangled.knot.memberAcceptance repo:sh.tangled.label.definition repo:sh.tangled.label.op repo:sh.tangled.publicKey repo:sh.tangled.repo repo:sh.tangled.repo.artifact repo:sh.tangled.repo.collaborator repo:sh.tangled.repo.collaboratorAcceptance repo:sh.tangled.repo.issue repo:sh.tangled.repo.issue.comment repo:sh.tangled.repo.issue.state repo:sh.tangled.repo.pull repo:sh.tangled.repo.pull.comment repo:sh.tangled.repo.pull.status repo:sh.tangled.spindle repo:sh.tangled.spindle.member repo:sh.tangled.string blob:*/* rpc:sh.tangled.graph.listNetworkVouches?aud=* rpc:sh.tangled.knot.acceptMembership?aud=* rpc:sh.tangled.knot.addMember?aud=* rpc:sh.tangled.knot.removeMember?aud=* rpc:sh.tangled.ci.triggerPipeline?aud=* rpc:sh.tangled.ci.cancelPipeline?aud=* rpc:sh.tangled.repo.acceptCollaboration?aud=* rpc:sh.tangled.repo.addCollaborator?aud=* rpc:sh.tangled.repo.addSecret?aud=* rpc:sh.tangled.repo.create?aud=* rpc:sh.tangled.repo.delete?aud=* rpc:sh.tangled.repo.deleteBranch?aud=* rpc:sh.tangled.repo.forkStatus?aud=* rpc:sh.tangled.repo.forkSync?aud=* rpc:sh.tangled.repo.hiddenRef?aud=* rpc:sh.tangled.repo.listSecrets?aud=* rpc:sh.tangled.repo.merge?aud=* rpc:sh.tangled.repo.mergeCheck?aud=* rpc:sh.tangled.repo.removeCollaborator?aud=* rpc:sh.tangled.repo.removeSecret?aud=* rpc:sh.tangled.repo.setDefaultBranch?aud=* rpc:org.tangled.temp.notification.getPreferences?aud=* rpc:org.tangled.temp.notification.updatePreferences?aud=* rpc:org.tangled.temp.notification.getUnreadCount?aud=* rpc:org.tangled.temp.notification.listNotifications?aud=* rpc:org.tangled.temp.notification.markAllRead?aud=* rpc:org.tangled.temp.notification.markEntityRead?aud=* rpc:org.tangled.temp.notification.updateSeen?aud=* rpc:org.tangled.temp.account.listEmails?aud=* rpc:org.tangled.temp.account.deleteEmail?aud=* rpc:org.tangled.temp.account.setPrimaryEmail?aud=* rpc:org.tangled.temp.account.addEmail?aud=* rpc:org.tangled.temp.account.verifyEmail?aud=* rpc:org.tangled.temp.site.getDomainClaim?aud=* rpc:org.tangled.temp.site.claimDomain?aud=* rpc:org.tangled.temp.site.releaseDomain?aud=* rpc:org.tangled.temp.search.searchCode?aud=* rpc:sh.tangled.git.keepCommit?aud=* rpc:sh.tangled.repo.push?aud=* rpc:sh.tangled.git.mergeCommit?aud=* rpc:sh.tangled.actor.getTrending?aud=* rpc:sh.tangled.feed.getTimeline?aud=* rpc:com.atproto.moderation.createReport?aud=*", - "grant_types": ["authorization_code", "refresh_token"], - "response_types": ["code"], - "token_endpoint_auth_method": "none", - "application_type": "web", - "dpop_bound_access_tokens": true -} diff --git a/web/src/lib/oauth-client-metadata.ts b/web/src/lib/oauth-client-metadata.ts new file mode 100644 index 000000000..ccad1fb51 --- /dev/null +++ b/web/src/lib/oauth-client-metadata.ts @@ -0,0 +1,86 @@ +const scopes = [ + "atproto", + "blob:*/*", + "repo:org.tangled.feed.subscription", + "repo:sh.tangled.actor.profile", + "repo:sh.tangled.feed.comment", + "repo:sh.tangled.feed.reaction", + "repo:sh.tangled.feed.star", + "repo:sh.tangled.graph.follow", + "repo:sh.tangled.graph.vouch", + "repo:sh.tangled.knot", + "repo:sh.tangled.knot.member", + "repo:sh.tangled.knot.memberAcceptance", + "repo:sh.tangled.label.definition", + "repo:sh.tangled.label.op", + "repo:sh.tangled.publicKey", + "repo:sh.tangled.repo", + "repo:sh.tangled.repo.artifact", + "repo:sh.tangled.repo.collaborator", + "repo:sh.tangled.repo.collaboratorAcceptance", + "repo:sh.tangled.repo.issue", + "repo:sh.tangled.repo.issue.comment", + "repo:sh.tangled.repo.issue.state", + "repo:sh.tangled.repo.pull", + "repo:sh.tangled.repo.pull.comment", + "repo:sh.tangled.repo.pull.status", + "repo:sh.tangled.spindle", + "repo:sh.tangled.spindle.member", + "repo:sh.tangled.string", + "rpc:com.atproto.moderation.createReport?aud=*", + "rpc:org.tangled.temp.account.addEmail?aud=*", + "rpc:org.tangled.temp.account.deleteEmail?aud=*", + "rpc:org.tangled.temp.account.listEmails?aud=*", + "rpc:org.tangled.temp.account.setPrimaryEmail?aud=*", + "rpc:org.tangled.temp.account.verifyEmail?aud=*", + "rpc:org.tangled.temp.notification.getPreferences?aud=*", + "rpc:org.tangled.temp.notification.getUnreadCount?aud=*", + "rpc:org.tangled.temp.notification.listNotifications?aud=*", + "rpc:org.tangled.temp.notification.markAllRead?aud=*", + "rpc:org.tangled.temp.notification.markEntityRead?aud=*", + "rpc:org.tangled.temp.notification.updatePreferences?aud=*", + "rpc:org.tangled.temp.notification.updateSeen?aud=*", + "rpc:org.tangled.temp.search.searchCode?aud=*", + "rpc:org.tangled.temp.site.claimDomain?aud=*", + "rpc:org.tangled.temp.site.getDomainClaim?aud=*", + "rpc:org.tangled.temp.site.releaseDomain?aud=*", + "rpc:sh.tangled.actor.getTrending?aud=*", + "rpc:sh.tangled.ci.cancelPipeline?aud=*", + "rpc:sh.tangled.ci.triggerPipeline?aud=*", + "rpc:sh.tangled.feed.getTimeline?aud=*", + "rpc:sh.tangled.git.keepCommit?aud=*", + "rpc:sh.tangled.git.mergeCommit?aud=*", + "rpc:sh.tangled.graph.listNetworkVouches?aud=*", + "rpc:sh.tangled.knot.acceptMembership?aud=*", + "rpc:sh.tangled.knot.addMember?aud=*", + "rpc:sh.tangled.knot.removeMember?aud=*", + "rpc:sh.tangled.repo.acceptCollaboration?aud=*", + "rpc:sh.tangled.repo.addCollaborator?aud=*", + "rpc:sh.tangled.repo.addSecret?aud=*", + "rpc:sh.tangled.repo.create?aud=*", + "rpc:sh.tangled.repo.delete?aud=*", + "rpc:sh.tangled.repo.deleteBranch?aud=*", + "rpc:sh.tangled.repo.forkStatus?aud=*", + "rpc:sh.tangled.repo.forkSync?aud=*", + "rpc:sh.tangled.repo.hiddenRef?aud=*", + "rpc:sh.tangled.repo.listSecrets?aud=*", + "rpc:sh.tangled.repo.merge?aud=*", + "rpc:sh.tangled.repo.mergeCheck?aud=*", + "rpc:sh.tangled.repo.push?aud=*", + "rpc:sh.tangled.repo.removeCollaborator?aud=*", + "rpc:sh.tangled.repo.removeSecret?aud=*", + "rpc:sh.tangled.repo.setDefaultBranch?aud=*" +]; + +export default { + client_id: "https://tangled.org/oauth-client-metadata.json", + client_name: "Tangled", + client_uri: "https://tangled.org", + redirect_uris: ["https://tangled.org/oauth/callback"], + grant_types: ["authorization_code", "refresh_token"], + response_types: ["code"], + token_endpoint_auth_method: "none", + application_type: "web", + dpop_bound_access_tokens: true, + scope: scopes.join(" ") +}; diff --git a/web/src/routes/oauth-client-metadata.json/+server.ts b/web/src/routes/oauth-client-metadata.json/+server.ts index 7bfce4184..b154969c4 100644 --- a/web/src/routes/oauth-client-metadata.json/+server.ts +++ b/web/src/routes/oauth-client-metadata.json/+server.ts @@ -1,5 +1,5 @@ import { json } from "@sveltejs/kit"; -import metadata from "$lib/oauth-client-metadata.json"; +import metadata from "$lib/oauth-client-metadata"; export const GET = ({ url }) => { const origin = url.origin; diff --git a/web/vite.config.ts b/web/vite.config.ts index ae4cd95c5..edc06c271 100644 --- a/web/vite.config.ts +++ b/web/vite.config.ts @@ -2,7 +2,7 @@ import tailwindcss from "@tailwindcss/vite"; import { sveltekit } from "@sveltejs/kit/vite"; import Icons from "unplugin-icons/vite"; import { defineConfig } from "vitest/config"; -import oauthMetadata from "./src/lib/oauth-client-metadata.json"; +import oauthMetadata from "./src/lib/oauth-client-metadata"; import path from "node:path"; import { fileURLToPath } from "node:url"; import { storybookTest } from "@storybook/addon-vitest/vitest-plugin"; -- 2.51.2