Repository navigation
Add Sorare adapter + LOGIN_TOKEN auth profile - #199
Merged
Merged
Conversation
Introduce a declarative LOGIN_TOKEN AuthType for APIs that issue a
long-lived bearer in exchange for a credentials POST, optionally
requiring the password to be bcrypt-hashed with a salt fetched from
the remote service (Sorare pattern).
The new LoginTokenService handles salt fetch + bcrypt + login +
in-memory & DB token caching + per-key mutex + proactive refresh +
forced re-login on 401. REST and GraphQL engines gain a LOGIN_TOKEN
case in injectAuth and an auto-relogin retry on 401. Tokens are
persisted encrypted (AES-256-GCM) in a new connector_auth_cache
table; cache survives restarts.
The Sorare adapter (packages/backend/src/adapters/intl/sorare.json)
ships 7 GraphQL tools over cards, players, lineups, and the transfer
market. The included LOGIN_TOKEN authConfig drives the entire flow
declaratively — no Sorare-specific code anywhere.
Documentation: docs/connectors/login-token-auth.md is the field-by-
field reference; docs/tool-definition.md gains a LOGIN_TOKEN section.
Twelve multilingual MDX guides (en/de/it × {ChatGPT, Claude, OpenClaw,
generic MCP}) cover end-user setup for each AI client.
Validated end-to-end against the live Sorare API: salt fetch + bcrypt
+ signIn returns a 30-day JWT, currentUser query succeeds with the
issued Authorization + JWT-AUD headers, cache hit + forceRelogin both
behave as expected.
All 704 backend tests pass (incl. 15 new login-token specs and
10 new catalog assertions for the Sorare adapter and LOGIN_TOKEN
validation).
keysersoft
force-pushed
the
keysersoft/sorare-connector-bcrypt
branch
from
May 18, 2026 13:36
8136cf4 to
18b295c
Compare
keysersoft
enabled auto-merge (squash)
May 18, 2026 13:36
1 of 2 tasks
keysersoft
added a commit
that referenced
this pull request
May 18, 2026
McpServerModule registers its own copy of RestEngine and GraphqlEngine as providers. After the Sorare PR added LoginTokenService as a constructor dependency of both engines, McpServerModule could no longer resolve them, causing UnknownDependenciesException at startup and an unhealthy app container. Adding LoginTokenService to McpServerModule's providers (alongside the existing OAuth2TokenService) fixes the startup crash. This is the root cause of the cloud outage following PR #199.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
LOGIN_TOKENAuthType: declarative spec for APIs that POST credentials → receive long-lived bearer, with optional client-side bcrypt against a per-account salt fetched from the remote service (Sorare pattern). Adapter authors describe the entire flow in JSON; no per-provider code.packages/backend/src/adapters/intl/sorare.json) with 7 GraphQL tools over cards, players, lineups, and the transfer market.Architecture
LoginTokenServicehandles salt fetch → bcrypt →signIn→ token cache (in-memory + encryptedconnector_auth_cacheDB row) → proactive refresh ≥24 h before expiry → forced re-login on 401, behind a per-key mutex.REST and GraphQL engines gain a
LOGIN_TOKENcase ininjectAuthplus a 401-retry path that callsforceRelogin()and re-issues the request once.Token persistence: new
ConnectorAuthCachePrisma model + migration (20260518000000_add_login_token_auth), AES-256-GCM encrypted at rest with the existingENCRYPTION_KEY.AdapterMetagains optionalfeatured?: booleanandpriority?: numberso the marketing site can rank Sorare on the home page without a code change there.Live validation
The same
LoginTokenServicecode in this PR was run against the real Sorare API:signInreturned a JWT withexpiredAtexactly 30 days out (732 ms)getToken()hit the cache in 0 mscurrentUserquery withAuthorization: Bearer+JWT-AUDreturned the authenticated profileforceRelogin()produced a fresh, different tokenTest plan
npm test— 704 backend tests pass (15 new login-token specs, 10 new catalog assertions for the Sorare adapter and LOGIN_TOKEN validation)npx tsc --noEmitcleannpx eslintclean on changed filesdeploy-cloud.ymlrebuilds the image;cloud.anythingmcp.com/connectorsshould list Sorare Fantasy Football in the catalogSORARE_EMAIL/SORARE_PASSWORD/SORARE_AUD, mint MCP key, callsorare_current_userfrom Claude / ChatGPT / OpenClaw → returns the user slugFiles
LoginTokenService+ spec, Sorare adapter JSON + intl/ folder, login-token auth docs, 12 MDX guides, Prisma migrationLOGIN_TOKEN, +ConnectorAuthCache), REST + GraphQL engines, connectors module, catalog.ts (+featured/priority), catalog.spec.ts (+LOGIN_TOKEN validation, +GraphQL method enum), tool-definition.md, two existing live-spec constructors updated for the newLoginTokenServicearg