| 911 | // createClient — write the oauth_client row. |
| 912 | // ----------------------------------------------------------------------- |
| 913 | const createClient = ( |
| 914 | input: CreateOAuthClientInput, |
| 915 | ): Effect.Effect<OAuthClientSlug, OrgWriteDeniedError | StorageFailure> => |
| 916 | Effect.gen(function* () { |
| 917 | // The `first-party:` namespace is reserved for config-declared apps — a |
| 918 | // stored row under it would be shadowed by (or worse, impersonate) the |
| 919 | // host's own app. |
| 920 | if (isFirstPartyOAuthClientSlug(String(input.slug))) { |
| 921 | return yield* new StorageError({ |
| 922 | message: `OAuth client slug "${String(input.slug)}" uses the reserved first-party namespace.`, |
| 923 | cause: undefined, |
| 924 | }); |
| 925 | } |
| 926 | yield* deps.guardOrgWrite(input.owner); |
| 927 | yield* validateClientEndpoints(input, deps.endpointUrlPolicy); |
| 928 | if ( |
| 929 | input.tokenEndpointAuthMethod !== undefined && |
| 930 | input.tokenEndpointAuthMethod !== "body" && |
| 931 | input.clientSecret.length === 0 |
| 932 | ) { |
| 933 | return yield* new StorageError({ |
| 934 | message: "HTTP Basic token endpoint authentication requires a client secret.", |
| 935 | cause: undefined, |
| 936 | }); |
| 937 | } |
| 938 | const keys = yield* Effect.try({ |
| 939 | try: () => deps.ownedKeys(input.owner), |
| 940 | catch: (cause) => |
| 941 | new StorageError({ |
| 942 | message: "Cannot write oauth_client for owner without a subject", |
| 943 | cause, |
| 944 | }), |
| 945 | }); |
| 946 | const now = new Date(); |
| 947 | |
| 948 | // Resolve the out-of-band write up front, but do not mutate the provider |
| 949 | // until the database transaction commits. |
| 950 | let clientSecretItemIdValue: string | null = null; |
| 951 | let credentialWrite: CredentialWriteAttempt | null = null; |
| 952 | let secretWrite: CredentialWriteSnapshot | undefined; |
| 953 | if (input.clientSecret.length > 0) { |
| 954 | const provider = deps.defaultWritableProvider(); |
| 955 | if (!provider || !provider.set) { |
| 956 | return yield* new StorageError({ |
| 957 | message: |
| 958 | "No default writable credential provider is registered to store the OAuth client secret.", |
| 959 | cause: undefined, |
| 960 | }); |
| 961 | } |
| 962 | const attemptId = crypto.randomUUID(); |
| 963 | credentialWrite = makeCredentialWriteAttempt(deps.credentialWriteRuntimeId, attemptId); |
| 964 | clientSecretItemIdValue = credentialAttemptItemId( |
| 965 | clientSecretItemId(input.owner, input.slug), |
| 966 | attemptId, |
| 967 | ); |
| 968 | const itemId = ProviderItemId.make(clientSecretItemIdValue); |
| 969 | const [snapshot] = yield* snapshotCredentialWrites( |
| 970 | { ...provider, set: provider.set }, |