Initial Checks
Release line
v2 (v1 shares the code)
Description
Two extensibility gaps in OAuthClientProvider for host applications that manage OAuth at scale (many servers, multi-tenant callbacks):
-
Endpoint override. The endpoints used by the flow are only ever taken from discovery metadata or hard-coded fallbacks. A host that already knows the correct endpoints (admin-configured connectors, servers with broken or absent RFC 8414 metadata) has no supported way to supply them — subclassing private methods is the only route today. Proposal: an optional OAuthEndpoints value (authorization/token/registration endpoints) accepted by the provider and taking precedence over discovery.
-
State generation hook. _perform_authorization_code_grant hard-codes state = secrets.token_urlsafe(32). A host that routes many callbacks through one shared redirect endpoint needs to bind the state value to its own session/tenant (e.g. a signed payload) while keeping the SDK's CSRF check. Proposal: an overridable generate_auth_state() hook defaulting to the current behavior.
Both are additive, no behavior change for existing users. We run both in production and can PR them — happy to be assigned.
🤖 Generated with Claude Code
Initial Checks
mainand 2.2.0)Release line
v2 (v1 shares the code)
Description
Two extensibility gaps in
OAuthClientProviderfor host applications that manage OAuth at scale (many servers, multi-tenant callbacks):Endpoint override. The endpoints used by the flow are only ever taken from discovery metadata or hard-coded fallbacks. A host that already knows the correct endpoints (admin-configured connectors, servers with broken or absent RFC 8414 metadata) has no supported way to supply them — subclassing private methods is the only route today. Proposal: an optional
OAuthEndpointsvalue (authorization/token/registration endpoints) accepted by the provider and taking precedence over discovery.State generation hook.
_perform_authorization_code_granthard-codesstate = secrets.token_urlsafe(32). A host that routes many callbacks through one shared redirect endpoint needs to bind thestatevalue to its own session/tenant (e.g. a signed payload) while keeping the SDK's CSRF check. Proposal: an overridablegenerate_auth_state()hook defaulting to the current behavior.Both are additive, no behavior change for existing users. We run both in production and can PR them — happy to be assigned.
🤖 Generated with Claude Code