From 5c9d1a0136cdc91ef713ef1b029778da6f3f192d Mon Sep 17 00:00:00 2001 From: clover caruso Date: Mon, 5 Oct 2026 10:45:51 -0700 Subject: [PATCH] Send the client ID in Astheno token exchanges Astheno requires the client_id form parameter even with client_secret_basic authentication. Log provider HTTP status and endpoint paths without credentials or response payloads. Assisted-by: gpt-6 --- dashboard/src/guest.rs | 9 ++++++++- 1 file changed, 8 insertions(+), 1 deletion(-) diff --git a/dashboard/src/guest.rs b/dashboard/src/guest.rs index 745eb2b1ea150401da3ad94880dd136477602803..513bcdddb103249ec37eed04c60d06ba1a022b8d 100644 --- a/dashboard/src/guest.rs +++ b/dashboard/src/guest.rs @@ -97,6 +97,12 @@ fn registration(auth: &auth::Store, provider: &str) -> Result<(String, String)> async fn response_bytes(mut response: reqwest::Response) -> Result> { if !response.status().is_success() || response.content_length().is_some_and(|n| n > 65536) { + eprintln!( + "guest provider response: {} {} status {}", + response.url().host_str().unwrap_or_default(), + response.url().path(), + response.status() + ); return Err(Error::new( 502, "The provider couldn't complete sign-in. Return to Shale and try again.", @@ -242,6 +248,7 @@ async fn exchange( flow: &Value, ) -> Result<(String, String)> { let form = [ + ("client_id", client), ("grant_type", "authorization_code"), ("code", code), ("redirect_uri", callback), @@ -249,7 +256,7 @@ async fn exchange( ]; if provider == "github" { let mut form = form.to_vec(); - form.extend([("client_id", client), ("client_secret", secret)]); + form.push(("client_secret", secret)); let token = json_bytes( &response_bytes( http.post("https://github.com/login/oauth/access_token") -- 2.54.0