Matthieu Sieben
8012627a12
Migrate OAuth libs to new @atproto/lex utils ( #4383 )
...
* Migrate Oauth libs to new @atproto/lex utils
* pnpm-lock
* tidy
* fix
* tidy
* tidy
* tidy
* tidy
* Implement lex resolution logging through hooks
2025-12-01 12:24:01 +01:00
Matthieu Sieben
bcae2b77b6
Increase string format typing strictness ( #4389 )
...
* Increase string format typing strictness
* fix tests
* tidy
* Use string formats from `@atproto/syntax`
* tidy
* `key` field in `record` definitions is non optional and now properly validated
* add missing /*@__NO_SIDE_EFFECTS__*/
2025-11-30 19:46:07 +01:00
Matthieu Sieben
1d445af2a7
lex SDK improvements ( #4390 )
...
* Add `l.nullable` schema builder
* Use unique symbol to describe Validator type metadata
* fixup! Add `l.nullable` schema builder
* Rework object validation logic to work without `options` argument
* Do not use symbol for type inference
* Use `Issue` classes to represent validation issues
* Properly apply default value with `const` and `enum` schemas
* style
* Require `l.discriminatedUnion` discriminator field to be a literal or enum schema
* Add `l.refined` schema
* Add more lexicons document validation tests
* wip
* use "assert" fn
* rework refine system
* use assert instead of check fn
* tidy
* Rename schema methods `validate`, `check` and `maybe` to `safeParse`, `matches` and `ifMatches` respectively.
* docs
* changeset
2025-11-30 14:35:15 +01:00
Matthieu Sieben
0adc852c31
Use arrays for "account" permission action attributes ( #4353 )
...
* Use arrays for "account" permission `action` attributes
* Allow lexicon permission data to be readonly
* changeset
* tidy
* tidy
* tidy
2025-11-25 21:48:10 +01:00
Matthieu Sieben
be8e6c1f25
Permission-sets pre-release changes ( #4382 )
...
* Remove ability to define `blob` permission in permission sets
* Disallow `rpc` permissions with specific `aud` in permission-sets
* Add `toScopes()` utility on `IncludeScope`
* tidy
2025-11-25 19:51:02 +01:00
github-actions[bot]
4dede90ea5
Version packages ( #4369 )
...
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2025-11-24 22:26:10 +01:00
Matthieu Sieben
261968fd65
New TS SDK ( #4366 )
...
* lex
* packaging
* moke packaging
* revert test changes
* do not build temp
* tidy
* automatically build the list of `@atproto/lex/com` lexicons
* fix build
* Remove "com" export
* ridy
* remove manifest option
* tidy
* rename
* tidy
* tidy
* tidy
* tests
* add procedure params
* stricter tests
* tidy
* Improve ui8 parsing
* tidy
* tidy
* code split
* code split
* fix reserved keywords conflict
* exclude packages/lex/src/tests/lexicons from lint
* reserved keywords
* safe identifier
* fix build
* move lib.js to src/lib.ts
* Move tests dir
* fix ci ?
* increast lint size
* Remove `Record` type alias for recordsz
* fix package json exports
* Add support for unsafe characters in defs and nsids
* tidy
* token tests
* tidy
* name consistency
* remove unused `unknownKeys` params option
* Fix "moving" keys in `DictSchema` (remove `IntersectionSchema`)
* REview comments
* adapt shebang in `env`
* Make sure union object have their $type property set in typings
* fix
* Improve typing of `UnknownTypedObject`
* lex improvements
* code reorg
* split lex-builder
* tidy
* improve packaging
* rename lex-validation to lex-schema
* lex client
* rename prettifier option
* add lex-client as dependency to "lex"
* Export client as part of main export
* re-write example app using @atproto/lex
* add missing lex-client to tsconfig
* tidy
* add "null" schema type
* Smaller bundle code footprint
* tidy
* correctness
* tidy
* code split and improved testing
* tidy
* refactor common utils
* test all implementations
* improve tests
* tidy
* fix build
* fixes
* tidy
* lint
* tests
* tidy
* fix oauth-example app
* tidy
* tidy
* tests
* tidy
* Return an actual `Uint8Array` from `fromBase64Node`
* tidy
* adapt xrpc-server
* Rename `Lex` to `LexValue`
* minor fixes
* fix tests
* fix tests
* tidy
* fix
* tidy
* tidy
* fix `verifyCidForBytes` implementation
* fix imports
* tidy
* split lex-json in own package
* make base64 tests faster
* Add interop tests
* lint error
* tidy
* tidy
* changeset
* implement lex-resolver and lex-install
* remove need for polyfill
* readme
* more details
* tidy
* allow specifying `service` header on a per request basis
* tidy
* tidy
* tidy
* tidy
* add custom/intersection validation schemas
* tidy
* tidy
* remive un-necessary util
* improve typing of `l.object` output
* make "name" required in lexicon method errors
* fix tests
* tidy
* tidy
* add error responses
* update readme
* add "like " to example
* readme improvements
* tidy
* error management improvements
* Improve error results
* tidy
* refactor
* tidy
* lock
* Update binary to `ts-lex`
* tidy
* tidy
* Add "Overview" section
* fix build
* update bin
* readme-improvements
* paul's feedback
* Update packages/lex/lex/README.md
Co-authored-by: Daniel Holmgren <dtholmgren@gmail.com >
* Update packages/lex/lex/README.md
Co-authored-by: Daniel Holmgren <dtholmgren@gmail.com >
* Update packages/lex/lex/README.md
Co-authored-by: Daniel Holmgren <dtholmgren@gmail.com >
* Update packages/lex/lex/README.md
Co-authored-by: Daniel Holmgren <dtholmgren@gmail.com >
* Update packages/lex/lex/README.md
Co-authored-by: Daniel Holmgren <dtholmgren@gmail.com >
* Initial plan
* Address README review comments
Co-authored-by: matthieusieben <813661+matthieusieben@users.noreply.github.com >
* Clarify client configuration inheritance behavior
Co-authored-by: matthieusieben <813661+matthieusieben@users.noreply.github.com >
* Document allowLegacyBlobs default and compatibility implications (#15 )
* Initial plan
* Add notes about default setting and compatibility for allowLegacyBlobs
Co-authored-by: matthieusieben <813661+matthieusieben@users.noreply.github.com >
---------
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com >
Co-authored-by: matthieusieben <813661+matthieusieben@users.noreply.github.com >
* Rename `Json` to `JsonValue` in lex-json package (#14 )
* Initial plan
* Rename Json to JsonValue in lex-json package and dependent packages
Co-authored-by: matthieusieben <813661+matthieusieben@users.noreply.github.com >
* Remove import alias for JsonValue in ipld.ts
Co-authored-by: matthieusieben <813661+matthieusieben@users.noreply.github.com >
---------
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com >
Co-authored-by: matthieusieben <813661+matthieusieben@users.noreply.github.com >
* Update packages/lex/lex/README.md
Co-authored-by: Paul Frazee <pfrazee@gmail.com >
* Update packages/lex/lex/README.md
Co-authored-by: Paul Frazee <pfrazee@gmail.com >
* Update packages/lex/lex/README.md
Co-authored-by: Paul Frazee <pfrazee@gmail.com >
* Update packages/lex/lex/README.md
Co-authored-by: Paul Frazee <pfrazee@gmail.com >
* Update packages/lex/lex/README.md
Co-authored-by: Paul Frazee <pfrazee@gmail.com >
* Update packages/lex/lex/README.md
Co-authored-by: Paul Frazee <pfrazee@gmail.com >
* review comments and fixes
* Add lex to the dockerfiles
* tidy
* changeset for lex packages
* tidy
* Tidy
* tidy
* tidy
* Move language parsing to lex-data
* tidy
* doctoc
* error handling
* tidy
* tidy
* tidy
* fix
---------
Co-authored-by: Daniel Holmgren <dtholmgren@gmail.com >
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com >
Co-authored-by: matthieusieben <813661+matthieusieben@users.noreply.github.com >
Co-authored-by: Paul Frazee <pfrazee@gmail.com >
2025-11-24 21:01:16 +01:00
github-actions[bot]
6f59d64aa1
Version packages ( #4320 )
...
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2025-11-05 12:33:24 -06:00
Matthieu Sieben
3202dce91b
oauth example app rework ( #4319 )
...
* oauth example app rework
* changeset
2025-10-30 16:08:57 +01:00
github-actions[bot]
632e1ba91f
Version packages ( #4313 )
...
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2025-10-29 10:04:09 -05:00
Matthieu Sieben
d764c54fe4
Minor oauth-client-browser-example improvements ( #4311 )
...
* Minor oauth-client-browser-example improvements
* pnpm lock
2025-10-28 16:00:06 +01:00
github-actions[bot]
a37a7de809
Version packages ( #4302 )
...
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2025-10-27 14:08:11 +01:00
Matthieu Sieben
f496fa2c4d
Set dark background on authorization pages <body> in dark mode ( #4301 )
...
* Set dark background on authorization pages `<body>` in dark mode
* tidy
2025-10-24 16:17:46 +02:00
github-actions[bot]
33435c2e83
Version packages ( #4298 )
...
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2025-10-24 13:02:23 +02:00
Matthieu Sieben
8ff5ec4caa
OAuth client validation improvements ( #4289 )
...
* OAuth client validation improvements
* Remove `isLocalHostname` export
* tidy
2025-10-24 12:53:03 +02:00
Matthieu Sieben
1e702ea675
Add account data in pwd reset hooks ( #4265 )
...
* Add account data in pwd reset hooks
* tidy
* tidy
* tidy
2025-10-24 12:50:34 +02:00
Matthieu Sieben
1a7bd8c0d2
Remove abortcontroller-polyfill from @atproto/oauth-client-expo ( #4300 )
...
* Remove `abortcontroller-polyfill` that was causing "Property 'DOMException' doesn't exist" errors
* changeset
2025-10-24 12:38:31 +02:00
Matthieu Sieben
8c03d75b6c
Remove un-implemented introspect endpoint from OAuth Server metadata ( #4293 )
...
Remove un-implemented `introspect` endpoint from OAuth Authorization Server metadata
2025-10-24 12:10:37 +02:00
Aaron Parecki
dca500186e
update links to ietf docs ( #4273 )
2025-10-14 14:43:01 -07:00
github-actions[bot]
bd469a6861
Version packages ( #4247 )
...
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2025-10-06 19:13:28 +02:00
Matthieu Sieben
e71d265dd4
Minor oauth jwk tweaks ( #4256 )
...
* Minor oauth jwk changes
* tidy
2025-10-06 15:45:05 +02:00
Matthieu Sieben
09439d7d68
OAuth client improvements ( #4216 )
...
* wip
* Various OAuth client & API improvements
* pnpm lock
* Minor typing improvements
* ci
* fix
2025-10-02 16:21:17 +02:00
Matthieu Sieben
f560cf2266
Allow "use" claims only in public jwk ( #4103 )
...
Disallow use of `use` claim in private JWK (replaced with `key_ops`)
2025-10-02 13:33:56 +02:00
Matthieu Sieben
fefe70126d
oauth-client-expo (#4220 )
...
* `oauth-client-expo`
* working on android
* remove example app
* tidy
* tidy
* Do not install full expo
* tidy
* chngeset
* chngeset
* load expo
* tidy
2025-10-02 11:59:16 +02:00
github-actions[bot]
778f76320e
Version packages ( #4229 )
...
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2025-09-26 11:51:16 -05:00
github-actions[bot]
4c4ee7208f
Version packages ( #4218 )
...
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2025-09-23 08:30:58 +02:00
Matthieu Sieben
7351589a31
Add onResetPasswordRequest and onResetPasswordConfirm hooks ( #4217 )
2025-09-22 19:38:38 +02:00
github-actions[bot]
d91988fe79
Version packages ( #4192 )
...
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2025-09-10 15:15:55 +02:00
Matthieu Sieben
cf4117966c
Fix call to onDecodeToken oauth verifier hook ( #4191 )
...
* Make `DpopProof` readonly
* Improve token verification error details
* Always log warnings when DPOP proof `htu` contains # or ?.
* Add missing initialization of `onDecodeToken` hook
* Add logging around scope dereferencing operations
2025-09-09 15:56:32 +02:00
github-actions[bot]
e216e87859
Version packages ( #4167 )
...
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2025-09-09 12:29:10 +02:00
Matthieu Sieben
8914f9abde
Allow encoding scope claims of oauth access token JWT ( #4149 )
...
* Refactor token decoding
* Add scope decoder to pds
* tidy
* tidy
* tidy
* tidy
* review changes
* Add scope normzlization utility
* wording in lexicon
* Add specific error
* style
* tidy
* Update `AccessTokenMode` enum values to be more meaningful
* tidy
* Update .changeset/brown-boxes-bow.md
Co-authored-by: devin ivy <devinivy@gmail.com >
* Add retry strategy
* lint
* lint
---------
Co-authored-by: devin ivy <devinivy@gmail.com >
2025-09-09 12:13:34 +02:00
Matthieu Sieben
d570db43d6
Pr/3654 ( #4186 )
...
* add ja to links title and availableLocales
* japanese translation messages.po
* update translation
social-appの翻訳に寄せる
* update translate
* Update packages/oauth/oauth-provider-ui/src/locales/ja/messages.po
Co-authored-by: Takayuki KUSANO <65759+tkusano@users.noreply.github.com >
* Update packages/oauth/oauth-provider-ui/src/locales/ja/messages.po
Co-authored-by: Takayuki KUSANO <65759+tkusano@users.noreply.github.com >
* Update packages/oauth/oauth-provider-ui/src/locales/ja/messages.po
Co-authored-by: Takayuki KUSANO <65759+tkusano@users.noreply.github.com >
* Update packages/oauth/oauth-provider-ui/src/locales/ja/messages.po
Co-authored-by: Takayuki KUSANO <65759+tkusano@users.noreply.github.com >
* add translation
* Japanese translation message.po from oauth-provider-frontend
* add ja to links title
* Update packages/oauth/oauth-provider-ui/src/locales/ja/messages.po
Co-authored-by: Takayuki KUSANO <65759+tkusano@users.noreply.github.com >
* Update packages/oauth/oauth-provider-ui/src/locales/ja/messages.po
Co-authored-by: Takayuki KUSANO <65759+tkusano@users.noreply.github.com >
* Update translation "Avatar"
* Add missing translation
* Add missing translation frontend
* Add changeset
* Enable JA
---------
Co-authored-by: L-tan <3786294+dolciss@users.noreply.github.com >
Co-authored-by: Takayuki KUSANO <65759+tkusano@users.noreply.github.com >
2025-09-09 12:09:18 +02:00
github-actions[bot]
39b319be94
Version packages ( #4157 )
...
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2025-09-02 10:36:51 +02:00
Matthieu Sieben
d54d278abd
Allow unexpected error to go through when fetching permission sets ( #4155 )
...
* Allow unexpected error to go through when fetching permission sets
* Log `cid` as string after succesful lexicon resolution
* Log `cid` and `uri` as string on successful lexicon resolution
2025-08-30 15:26:28 +02:00
github-actions[bot]
c2dc0ec11b
Version packages ( #4154 )
...
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2025-08-29 16:05:17 +02:00
github-actions[bot]
920f895807
Version packages ( #4152 )
...
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2025-08-29 12:54:51 +02:00
Matthieu Sieben
86c4699da8
Improve oauth client callback handling ( #4150 )
2025-08-29 12:45:35 +02:00
Matthieu Sieben
f9dc9aa4c9
Permission set ( #4108 )
...
* Export constants and type assertion utilities
* Add permission set support to oauth provider
* improve permission set parsing
* Rename `PermissionSet` to `ScopePermissions`
* Improve performance of NSID validation
* Add support for `permission-set` in lexicon document
* Validate NSID syntax using `@atproto/syntax`
* Export all types used in public interfaces (from `lexicon-resolver`)
* Small performance improvement
* Rework scope parsing utilities to work with Lexicon defined permissions
* file rename
* fixup! Rework scope parsing utilities to work with Lexicon defined permissions
* removed outdated comment
* removed outdated comment
* fix comment typo
* Improve `SimpleStore` api
* permission-set NSID auth scopes
* Remove dev dependency on dev-env
* fix build script
* pnpm-lock
* Improve fetch-node unicast protection
* Explicitly set the `redirect: "follow"` `fetch()` option
* Add delay when building oauth-provider-ui in watch mode
* Remove external dependencies from auth-scopes
* Add customizable lexicon authority to pds (for dev purposes)
* fix pds migration
* update permission-set icon
* Add support for `include:` syntax in scopes
* tidy
* Renaming of "resource" concept to better reflect the fact that not all oauth scope values are about resources
* changeset
* ui improvmeents
* i18n
* ui imporvements
* add `AtprotoAudience` type
* Enforce proper formatting of audience (atproto supported did + fragment part)
* tidy
* tidy
* tidy
* fix ci ?
* ci fix ?
* tidy ?
* Apply consistent outline around focusable items
* Use `inheritAud: true` to control `aud` inheritance
* Update packages/oauth/oauth-provider/src/lexicon/lexicon-manager.ts
Co-authored-by: devin ivy <devinivy@gmail.com >
* Review comments
* Add `nsid` property to `LexiconResolutionError`
* improve nsid validation
* i18n
* Improve oauth scope parsing
* Simplify lex scope parsing
* tidy
* docs
* tidy
* ci
* Code simplification
* tidy
* improve type safety
* improve deps graph
* naming
* Improve tests and package structure
* Improve error when resolving a non permission-set
* improve nsid parsing perfs
* benchmark
* Refactor ozone and lexicon into using a common service profile mechanism
* improve perfs
* ci fix (?)
* tidy
* Allow storage of valid lexicons in lexicon store
* Improve handling of lexicon resolution failures
* review comment
* Test both regexp and non regexp based nsid validation
* properly detect presence of port number in https did:web
* Re-enable logging of `safeFetch` requests
* tidy
---------
Co-authored-by: devin ivy <devinivy@gmail.com >
2025-08-29 12:19:19 +02:00
Matthieu Sieben
f65afa33f5
Support multiple redirect URIs for @atproto/oauth-client-browser #4144 ( #4147 )
...
* Support multiple redirect URIs for @atproto/oauth-client-browser
* For redirect_uri callback parameter type
* fix-type-error
* Do not fail if the client can't figure out which redirect uri was used (and only one is available)
---------
Co-authored-by: Emelia Smith <ThisIsMissEm@users.noreply.github.com >
2025-08-28 17:57:38 +02:00
github-actions[bot]
768e81b232
Version packages ( #4126 )
...
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2025-08-27 13:36:05 -04:00
Emelia Smith
6231c8730a
Fix #4136 : Support multiple redirect URIs in @atproto/oauth-client ( #4139 )
...
* Fix #4136 : Support multiple redirect URIs in @atproto/oauth-client
* Fix type error in exchangeCode
2025-08-27 14:42:25 +02:00
Matthieu Sieben
9d22305f71
Fix circular dev dependencies and build scripts ( #4124 )
...
* fix build script
* Remove dev dependency on dev-env
* pnpm-lock
2025-08-21 16:02:54 +02:00
github-actions[bot]
5188ef3b59
Version packages ( #4116 )
...
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2025-08-20 21:48:51 +02:00
github-actions[bot]
d02d43c05b
Version packages ( #4102 )
...
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2025-08-13 15:22:03 +02:00
Matthieu Sieben
8a88e2c154
Add support for legacy JWKS validation in OAuth configuration ( #4101 )
...
* Remore requirement for JWK to define either `use` or `key_ops`
* Prevent inconsistent use of `use` and `key_ops` in JWK
* docs
* review comments
* comment
2025-08-13 15:15:54 +02:00
github-actions[bot]
f8667835db
Version packages ( #4099 )
...
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2025-08-13 10:30:51 +02:00
Matthieu Sieben
832866c33b
Enforce stronger validation of jwks loaded through their own uri ( #4100 )
...
* Enforce stronger validation of jwks loaded through their own uri
* add some docs
2025-08-13 09:45:23 +02:00
Matthieu Sieben
396ab57ed0
Fix warnings during build ( #4096 )
...
* Fix warnings during build
* Update caniuse-lite
2025-08-12 17:15:23 +02:00
Matthieu Sieben
c274bd1b38
Fix permission bug with transition:email scope ( #4097 )
...
* Fix permission bug with `transition:email` scope
* fix tests
2025-08-12 17:14:51 +02:00
github-actions[bot]
174f86da5f
Version packages ( #4094 )
...
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2025-08-12 14:45:00 +02:00