Skip to content

OAuthClientProvider: no supported way to override endpoints or customize authorization state generation #3570

Description

@dgilman-perplexity

Initial Checks

  • I confirm that I'm using the newest release of my line (verified on main and 2.2.0)
  • I confirm that I searched for my issue in the issues before opening this one (searched "custom oauth endpoints", "generate_auth_state", "state hook")

Release line

v2 (v1 shares the code)

Description

Two extensibility gaps in OAuthClientProvider for host applications that manage OAuth at scale (many servers, multi-tenant callbacks):

  1. Endpoint override. The endpoints used by the flow are only ever taken from discovery metadata or hard-coded fallbacks. A host that already knows the correct endpoints (admin-configured connectors, servers with broken or absent RFC 8414 metadata) has no supported way to supply them — subclassing private methods is the only route today. Proposal: an optional OAuthEndpoints value (authorization/token/registration endpoints) accepted by the provider and taking precedence over discovery.

  2. State generation hook. _perform_authorization_code_grant hard-codes state = secrets.token_urlsafe(32). A host that routes many callbacks through one shared redirect endpoint needs to bind the state value to its own session/tenant (e.g. a signed payload) while keeping the SDK's CSRF check. Proposal: an overridable generate_auth_state() hook defaulting to the current behavior.

Both are additive, no behavior change for existing users. We run both in production and can PR them — happy to be assigned.

🤖 Generated with Claude Code

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions