Files
Claude 8b77d1bfb6 feat(v4.6.0): one-click OAuth — PKCE + cloud broker, drop secret-paste UX
Replaces the painful "register your own OAuth app, paste client_id +
client_secret" flow with click-Authorize-and-done. Two completion
paths:

PKCE (no broker, no secrets)
- Used for providers that support OAuth 2.1 PKCE: Linear today;
  Atlassian / Microsoft / Google / Twitter / Discord drop in once each
  is registered.
- Local hub generates code_verifier, sends sha256 challenge to the
  provider, exchanges code + verifier on the callback. No secret in
  the binary.

Broker-mediated (autoMate Cloud or self-hosted)
- For providers that still require a confidential client at the token
  endpoint: GitHub, Notion, Slack, 飞书, 钉钉.
- Hosted broker (cloud/oauth_broker/) holds client_secret per
  provider; local hub never sees it. Flow:
    local → broker /start → provider → broker /callback (exchanges
    code for token, stashes by flow_id) → user-browser bounce back to
    local with flow_id → local fetches token via broker /result
    (single-use, deleted on read).
- Default broker URL is https://broker.automate.cloud; override with
  AUTOMATE_OAUTH_BROKER_URL for self-hosted.
- Tokens live in the broker's memory only during the ~30s in-flight
  window; flow_id is the only secret in transit (HTTPS).

Tools tab UI
- Each card has ONE "Connect" button.
- OAuth modal: a single big "Authorize with X" button. Click opens a
  popup at the provider's consent page; on success the callback page
  posts a message to the opener and self-closes; the modal updates to
  ✓ Connected without a refresh.
- API-key path: a single big deep-link button to the EXACT token
  page (with scopes pre-selected for GitHub etc.) + one paste field.
- Removed: client_id + client_secret inputs, "Use OAuth instead
  (advanced)" toggle, the /api/integrations/<id>/oauth-app endpoint.

Standalone broker (cloud/oauth_broker/)
- Tiny FastAPI app, deployable as a Docker image (Dockerfile +
  requirements.txt included) or `pip install -r requirements.txt &
  uvicorn main:app`.
- Reads OAUTH_<PROVIDER>_CLIENT_ID/SECRET from env, plus
  PUBLIC_BASE_URL.
- Exposes /oauth/<p>/start, /oauth/<p>/callback, /oauth/result, /health.
- Per-provider OAuth scopes are hardcoded in main.py:SPECS.

Docs
- docs/oauth-broker.md walks maintainers/self-hosters through the
  deployment + per-provider OAuth app registration.

When the broker is unreachable the OAuth modal degrades gracefully:
clear error message + "Or paste an API key instead" expandable that
deep-links to the provider's PAT page. OAuth and API-key flows produce
identical end-state in the connections table.

https://claude.ai/code/session_019uRjfdjRsVwG9iNbc5gJmN
2026-04-28 07:55:55 +00:00
..