authorgravatar for git@paperclover.netclover caruso <git@paperclover.net> 2026-10-05 10:45:51-07:00
committergravatar for git@paperclover.netclover caruso <git@paperclover.net> 2026-10-05 15:36:02-07:00
log5c9d1a0136cdc91ef713ef1b029778da6f3f192d
tree8e6dac1e751a14b5ac2df7f099be0fc0c4bf0eaa
parent692d41a6eabb6e6a88da2770eb3fc61e00dd75dd
signature Signed by SSH key SHA256:52mNGHRsVFBDED9IAX5pe+LRWUefqTbxEReunq21QvU

Send the client ID in Astheno token exchanges

Astheno requires the client_id form parameter even with client_secret_basic authentication. Log provider HTTP status and endpoint paths without credentials or response payloads. Assisted-by: gpt-6

1 files changed, 8 insertions(+), 1 deletions(-)

dashboard/src/guest.rs+8-1
......@@ -97,6 +97,12 @@ fn registration(auth: &auth::Store, provider: &str) -> Result<(String, String)>
9797
9898async fn response_bytes(mut response: reqwest::Response) -> Result<Vec<u8>> {
9999 if !response.status().is_success() || response.content_length().is_some_and(|n| n > 65536) {
100 eprintln!(
101 "guest provider response: {} {} status {}",
102 response.url().host_str().unwrap_or_default(),
103 response.url().path(),
104 response.status()
105 );
100106 return Err(Error::new(
101107 502,
102108 "The provider couldn't complete sign-in. Return to Shale and try again.",
......@@ -242,6 +248,7 @@ async fn exchange(
242248 flow: &Value,
243249) -> Result<(String, String)> {
244250 let form = [
251 ("client_id", client),
245252 ("grant_type", "authorization_code"),
246253 ("code", code),
247254 ("redirect_uri", callback),
......@@ -249,7 +256,7 @@ async fn exchange(
249256 ];
250257 if provider == "github" {
251258 let mut form = form.to_vec();
252 form.extend([("client_id", client), ("client_secret", secret)]);
259 form.push(("client_secret", secret));
253260 let token = json_bytes(
254261 &response_bytes(
255262 http.post("https://github.com/login/oauth/access_token")