Skip to content

[P2] Distinguish browser handoff codes from legacy proxy credentials in setup docs #60

Description

@michielbdejong

Recorded during review of main at a1eb305ccfa2f3fc8ddede4875765cf1b099bd2b. This issue records a finding only; no implementation changes were made or requested.

Finding

The README tells callers to use the connection_code returned by the OAuth redirect directly as a proxy Bearer token. That applies to the legacy flow only. In the browser bootstrap flow, the callback returns a PKCE-bound handoff that must first be redeemed at /connect/redeem. Following the generic instruction breaks new browser clients.

Evidence

Desired outcome

Document the two protocols separately, showing redemption before proxy use for browser clients and identifying the legacy behavior explicitly.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions