Skip to content

Add generic apiKey security-scheme support alongside OAuth - #74

Merged
michielbdejong merged 3 commits into
mainfrom
clockify-api-key-scheme
Sep 16, 2026
Merged

michielbdejong merged 3 commits into
mainfrom
clockify-api-key-scheme

Conversation

@michielbdejong

Copy link
Copy Markdown
Contributor

Summary

  • Adds ApiKeyScheme/SecurityScheme (providers.rs), resolved generically from a platform's composed OpenAPI securitySchemes — no platform-specific behavior, per AGENTS.md.
  • New browser-submitted-key branch in connect.rs's consent/authorize flow completes the existing PKCE handoff without any third-party redirect.
  • Unifies the previously duplicated OAuth credential struct (oauth.rs/proxy.rs) into one StoredCredential enum, so proxy.rs::forward can inject a static key via its declared header/query name instead of always assuming Authorization: Bearer.
  • Enables onboarding Clockify (and future apiKey-only platforms) via localthought/overlays; see companion PRs there and in localthought/openapi-directory.

Test plan

  • cargo fmt --all -- --check
  • cargo clippy --all-targets --all-features -- -D warnings
  • cargo test -- --include-ignored against a local Postgres (114/114 passing), including two new end-to-end tests exercising the full apiKey consent→authorize→redeem→forward flow

Michiel de Jong added 3 commits September 16, 2026 16:26
Clockify (and other static-key APIs) have no OAuth2 login, only a
personal secret sent as a declared header/query parameter. The proxy
previously assumed every catalog platform was OAuth2, from the
consent-page provider gate through credential storage to how a
proxied request's Authorization header was built.

Add ApiKeyScheme/SecurityScheme (providers.rs) resolved generically
from a platform's composed OpenAPI securitySchemes, a Catalog::security_scheme
accessor, a browser-submitted-key branch in connect.rs's consent/authorize
flow that completes the existing PKCE handoff without any third-party
redirect, and a StoredCredential enum (unifying the previously duplicated
OAuth credential struct in oauth.rs/proxy.rs) so proxy.rs::forward can
inject a static key via its declared header/query name instead of always
assuming Authorization: Bearer.

No platform-specific behavior was added here; Clockify's own catalog
entry belongs in localthought/overlays.
Missed from the previous commit: proves security_scheme()/allows()/
required_headers() resolve a real composed apiKey document correctly,
mirroring this file's existing pinned-fixture test pattern.
# Conflicts:
#	src/proxy.rs
#	src/templates.rs
@michielbdejong
michielbdejong merged commit cc1a13b into main Sep 16, 2026
1 check passed
@michielbdejong
michielbdejong deleted the clockify-api-key-scheme branch September 16, 2026 16:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant