Skip to content

feat: SDKCore - implement handlePostRedirect() - authorization code grant finished (ENG-4800)#204

Draft
mrudatsprint wants to merge 2 commits into
miker/eng-4786/code-grant-startfrom
miker/eng-4800/code-grant-finish
Draft

feat: SDKCore - implement handlePostRedirect() - authorization code grant finished (ENG-4800)#204
mrudatsprint wants to merge 2 commits into
miker/eng-4786/code-grant-startfrom
miker/eng-4800/code-grant-finish

Conversation

@mrudatsprint

Copy link
Copy Markdown
Collaborator

What is this PR and why do we need it?

-https://linear.app/fusionauth/issue/ENG-4786/sdkcore-implement-startlogin-authorization-code-grant

Pre-Merge Checklist (if applicable)

  • Unit and Feature tests have been added/updated for logic changes, or there is a justifiable reason for not doing so.

…ange (ENG-4800)

- UrlHelper.getTokenUrl() targets FusionAuth's /oauth2/token directly.
- DPoPManager.getExpiresAt() exposes the stored token's expiry (-1 when
  none), mirroring CookieHelpers' convention.
- SDKCore.handlePostRedirect() branches into handleDpopPostRedirect() in
  DPoP mode: detects the `code` query param, retrieves the persisted PKCE
  code_verifier, signs a DPoP proof for the token endpoint (no ath),
  POSTs the authorization_code grant, stores the returned tokens, and
  schedules token expiration + (when shouldAutoRefresh) auto-refresh from
  expiresAt. No-ops silently when code/code_verifier is missing (e.g. a
  second invocation after a successful exchange). Failures report via
  onLoginFailure/console.error, mirroring startLogin().
- SDKCore.at_exp generalized to delegate to DPoPManager.getExpiresAt() in
  DPoP mode so scheduling logic is shared between cookie and DPoP modes.
- Unit tests for all of the above; mockWindowLocation extended to accept
  a search override for simulating the post-redirect landing.
- e2e/tests/dpop-smoke.test.ts: extracted shared ensureNodeBrowserPolyfills()
  helper; updated T1-2 to drive the full authorization code grant through
  the real SDKCore.startLogin() + handlePostRedirect() against a live
  FusionAuth instance instead of replicating the exchange manually.
@mrudatsprint
mrudatsprint changed the base branch from main to miker/eng-4786/code-grant-start July 21, 2026 21:44
@mrudatsprint mrudatsprint changed the title feat: SDKCore: implement startLogin() - authorization code grant start feat: SDKCore - implement handlePostRedirect() - authorization code exchange finished Jul 21, 2026
@mrudatsprint mrudatsprint changed the title feat: SDKCore - implement handlePostRedirect() - authorization code exchange finished feat: SDKCore - implement handlePostRedirect() - authorization code grant finished (ENG-4800) Jul 21, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant