// The app's OAuth client metadata, derived from scope.ts so the hosted JSON // (emitted by tools/build-webapp.ts), the running app, and the scope tests // can never drift — the same single-source rule that ended the desktop's // scope bugs. app.ziran.space is a public browser client: no secret, DPoP // everywhere, tokens live in the browser. import { ZIRAN_SCOPE } from '../sync/spaces/scope.ts'; export const APP_ORIGIN = 'https://app.ziran.space'; export const CLIENT_ID = `${APP_ORIGIN}/oauth-client-metadata.json`; export function clientMetadata() { return { client_id: CLIENT_ID, client_name: 'Ziran', client_uri: APP_ORIGIN, redirect_uris: [`${APP_ORIGIN}/`] as [string], scope: ZIRAN_SCOPE, grant_types: ['authorization_code', 'refresh_token'] as ['authorization_code', 'refresh_token'], response_types: ['code'] as ['code'], token_endpoint_auth_method: 'none' as const, application_type: 'web' as const, dpop_bound_access_tokens: true, }; }