Recorded during review of main at a1eb305ccfa2f3fc8ddede4875765cf1b099bd2b. This issue records a finding only; no implementation changes were made or requested.
Finding
The README tells callers to use the connection_code returned by the OAuth redirect directly as a proxy Bearer token. That applies to the legacy flow only. In the browser bootstrap flow, the callback returns a PKCE-bound handoff that must first be redeemed at /connect/redeem. Following the generic instruction breaks new browser clients.
Evidence
Desired outcome
Document the two protocols separately, showing redemption before proxy use for browser clients and identifying the legacy behavior explicitly.
Recorded during review of main at
a1eb305ccfa2f3fc8ddede4875765cf1b099bd2b. This issue records a finding only; no implementation changes were made or requested.Finding
The README tells callers to use the
connection_codereturned by the OAuth redirect directly as a proxy Bearer token. That applies to the legacy flow only. In the browser bootstrap flow, the callback returns a PKCE-bound handoff that must first be redeemed at/connect/redeem. Following the generic instruction breaks new browser clients.Evidence
Desired outcome
Document the two protocols separately, showing redemption before proxy use for browser clients and identifying the legacy behavior explicitly.