From 036a0e63f8c0eaa73960243300cfd238c1553210 Mon Sep 17 00:00:00 2001 From: clover caruso Date: Mon, 5 Oct 2026 10:49:49 -0700 Subject: [PATCH] Send Astheno client credentials in the token request body The live endpoint requires client_id and client_secret form fields despite advertising client_secret_basic. Share the same form credentials with GitHub and log only provider HTTP status and endpoint paths. Assisted-by: gpt-6 --- dashboard/src/guest.rs | 4 +--- 1 file changed, 1 insertion(+), 3 deletions(-) diff --git a/dashboard/src/guest.rs b/dashboard/src/guest.rs index 513bcdddb103249ec37eed04c60d06ba1a022b8d..ff3a9d367ebcec95bec221c74f15be407ce9f7e9 100644 --- a/dashboard/src/guest.rs +++ b/dashboard/src/guest.rs @@ -249,14 +249,13 @@ async fn exchange( ) -> Result<(String, String)> { let form = [ ("client_id", client), + ("client_secret", secret), ("grant_type", "authorization_code"), ("code", code), ("redirect_uri", callback), ("code_verifier", string(&flow["verifier"])), ]; if provider == "github" { - let mut form = form.to_vec(); - form.push(("client_secret", secret)); let token = json_bytes( &response_bytes( http.post("https://github.com/login/oauth/access_token") @@ -309,7 +308,6 @@ async fn exchange( let token = json_bytes( &response_bytes( http.post(format!("{ASTHENO}/api/token")) - .basic_auth(client, Some(secret)) .form(&form) .send() .await?, -- 2.54.0