feat: SDKCore - implement handlePostRedirect() - authorization code grant finished (ENG-4800)#204
Draft
mrudatsprint wants to merge 2 commits into
Draft
Conversation
…ange (ENG-4800) - UrlHelper.getTokenUrl() targets FusionAuth's /oauth2/token directly. - DPoPManager.getExpiresAt() exposes the stored token's expiry (-1 when none), mirroring CookieHelpers' convention. - SDKCore.handlePostRedirect() branches into handleDpopPostRedirect() in DPoP mode: detects the `code` query param, retrieves the persisted PKCE code_verifier, signs a DPoP proof for the token endpoint (no ath), POSTs the authorization_code grant, stores the returned tokens, and schedules token expiration + (when shouldAutoRefresh) auto-refresh from expiresAt. No-ops silently when code/code_verifier is missing (e.g. a second invocation after a successful exchange). Failures report via onLoginFailure/console.error, mirroring startLogin(). - SDKCore.at_exp generalized to delegate to DPoPManager.getExpiresAt() in DPoP mode so scheduling logic is shared between cookie and DPoP modes. - Unit tests for all of the above; mockWindowLocation extended to accept a search override for simulating the post-redirect landing. - e2e/tests/dpop-smoke.test.ts: extracted shared ensureNodeBrowserPolyfills() helper; updated T1-2 to drive the full authorization code grant through the real SDKCore.startLogin() + handlePostRedirect() against a live FusionAuth instance instead of replicating the exchange manually.
mrudatsprint
changed the base branch from
main
to
miker/eng-4786/code-grant-start
July 21, 2026 21:44
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What is this PR and why do we need it?
-https://linear.app/fusionauth/issue/ENG-4786/sdkcore-implement-startlogin-authorization-code-grant
Pre-Merge Checklist (if applicable)