feat(oauth): Phase B — claude.ai protocol compatibility

Add 3 features for claude.ai Connectors compatibility:

- FEATURE-3: client_secret_basic auth on token endpoint (RFC 6749 §2.3.1)
- FEATURE-2: Token revocation endpoint /oauth/revoke (RFC 7009)
- FEATURE-4: resource parameter support with JWT aud claim (RFC 8707)

23 new tests (481 total), all passing.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
This commit is contained in:
airano
2026-02-24 20:49:23 +03:30
parent 1736779d69
commit d3bcb31053
8 changed files with 852 additions and 3 deletions

View File

@@ -54,7 +54,12 @@ class TokenManager:
self.refresh_token_ttl = int(os.getenv("OAUTH_REFRESH_TOKEN_TTL", "604800")) # 7 days
def generate_access_token(
self, client_id: str, scope: str, user_id: str | None = None, project_id: str = "*"
self,
client_id: str,
scope: str,
user_id: str | None = None,
project_id: str = "*",
resource: str | None = None,
) -> str:
"""
Generate JWT access token.
@@ -64,6 +69,7 @@ class TokenManager:
scope: Granted scopes (space-separated)
user_id: User ID (optional, for user-based auth)
project_id: Project ID for scoping (default: "*" for global)
resource: Resource indicator for aud claim (RFC 8707)
Returns:
JWT access token
@@ -87,6 +93,9 @@ class TokenManager:
if user_id:
payload["sub"] = user_id # Subject (user ID)
if resource:
payload["aud"] = resource
# Encode JWT
token = jwt.encode(payload, self.jwt_secret, algorithm=self.jwt_algorithm)