mirror of
https://github.com/yuruotong1/autoMate.git
synced 2026-10-07 15:38:33 +08:00
Replaces the painful "register your own OAuth app, paste client_id +
client_secret" flow with click-Authorize-and-done. Two completion
paths:
PKCE (no broker, no secrets)
- Used for providers that support OAuth 2.1 PKCE: Linear today;
Atlassian / Microsoft / Google / Twitter / Discord drop in once each
is registered.
- Local hub generates code_verifier, sends sha256 challenge to the
provider, exchanges code + verifier on the callback. No secret in
the binary.
Broker-mediated (autoMate Cloud or self-hosted)
- For providers that still require a confidential client at the token
endpoint: GitHub, Notion, Slack, 飞书, 钉钉.
- Hosted broker (cloud/oauth_broker/) holds client_secret per
provider; local hub never sees it. Flow:
local → broker /start → provider → broker /callback (exchanges
code for token, stashes by flow_id) → user-browser bounce back to
local with flow_id → local fetches token via broker /result
(single-use, deleted on read).
- Default broker URL is https://broker.automate.cloud; override with
AUTOMATE_OAUTH_BROKER_URL for self-hosted.
- Tokens live in the broker's memory only during the ~30s in-flight
window; flow_id is the only secret in transit (HTTPS).
Tools tab UI
- Each card has ONE "Connect" button.
- OAuth modal: a single big "Authorize with X" button. Click opens a
popup at the provider's consent page; on success the callback page
posts a message to the opener and self-closes; the modal updates to
✓ Connected without a refresh.
- API-key path: a single big deep-link button to the EXACT token
page (with scopes pre-selected for GitHub etc.) + one paste field.
- Removed: client_id + client_secret inputs, "Use OAuth instead
(advanced)" toggle, the /api/integrations/<id>/oauth-app endpoint.
Standalone broker (cloud/oauth_broker/)
- Tiny FastAPI app, deployable as a Docker image (Dockerfile +
requirements.txt included) or `pip install -r requirements.txt &
uvicorn main:app`.
- Reads OAUTH_<PROVIDER>_CLIENT_ID/SECRET from env, plus
PUBLIC_BASE_URL.
- Exposes /oauth/<p>/start, /oauth/<p>/callback, /oauth/result, /health.
- Per-provider OAuth scopes are hardcoded in main.py:SPECS.
Docs
- docs/oauth-broker.md walks maintainers/self-hosters through the
deployment + per-provider OAuth app registration.
When the broker is unreachable the OAuth modal degrades gracefully:
clear error message + "Or paste an API key instead" expandable that
deep-links to the provider's PAT page. OAuth and API-key flows produce
identical end-state in the connections table.
https://claude.ai/code/session_019uRjfdjRsVwG9iNbc5gJmN