Skip to content

[18.0][BKP] webservice: configurable OAuth2 token request - #169

Open
Ricardoalso wants to merge 5 commits into
OCA:18.0from
camptocamp:18.0-imp-webservice-oauth2-client-auth
Open

Ricardoalso wants to merge 5 commits into
OCA:18.0from
camptocamp:18.0-imp-webservice-oauth2-client-auth

Conversation

@Ricardoalso

@Ricardoalso Ricardoalso commented Sep 24, 2026 •

Copy link
Copy Markdown

ivantodorovich and others added 4 commits September 23, 2026 16:18
Until now the OAuth2 "Backend Application (Client Credentials)" flow
always requested the token in one fixed way: an HTTP POST where the
client id and secret were turned into an HTTP Basic Authorization header
(this is what oauthlib does by default). Providers that deviate from
that could not be used.

Two configuration options are added to the webservice backend so those
providers can be supported through configuration only:

- Token Request Method: POST (default) or GET, for providers that expose
  the token endpoint as a GET.

- Client Authentication: how the client credentials are presented to the
  token endpoint:
    * Client ID & Secret (HTTP Basic) (default): the previous behavior,
      unchanged.
    * Custom Authorization header: a static, verbatim header value (for
      example "SSWS <token>"). In this case the Client ID / Client Secret
      fields are not used; the header name and value are configured
      directly instead.

The defaults keep the exact same behavior as before, so existing
backends are not affected. The custom header is injected through a small
requests auth handler so that oauthlib does not overwrite it with its
automatic Basic Authorization header.

Two validation rules make sure the right fields are filled in depending
on the chosen client authentication: the client id and secret for the
HTTP Basic method, or the header name and value for the custom header
method.
There was a misuse of `and` instead of `or` in the `invisible` attribute of some
fields that are specific to the Web Application flow
The webservice module gained new OAuth2 configuration fields (the token
request method, the client authentication method, and the custom
Authorization header name and value). These are now also manageable
through server environment configuration files, like the other
webservice fields.
@OCA-git-bot

Copy link
Copy Markdown
Contributor

Hi @etobella, @simahawk,
some modules you are maintaining are being modified, check this out!

@Ricardoalso
Ricardoalso marked this pull request as draft September 24, 2026 11:31
@OCA-git-bot OCA-git-bot added mod:webservice Module webservice mod:webservice_server_env Module webservice_server_env series:18.0 mod:webservice_core Module webservice_core labels Sep 24, 2026
@Ricardoalso
Ricardoalso force-pushed the 18.0-imp-webservice-oauth2-client-auth branch from 7023860 to 0587941 Compare September 24, 2026 18:52
@Ricardoalso
Ricardoalso marked this pull request as ready for review September 24, 2026 18:59
@Ricardoalso

Ricardoalso commented Sep 24, 2026 •

Copy link
Copy Markdown
Author

@ivantodorovich if you wanna take a look 🙏

The objective here is to ease the FW port to 19.0 of [18.0][REF] webservice: split core to webservice_core #164

@ivantodorovich

Copy link
Copy Markdown
Contributor

Thanks!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

mod:webservice_core Module webservice_core mod:webservice_server_env Module webservice_server_env mod:webservice Module webservice series:18.0

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants