Skip to content

fix: encode revocation requests and preserve discovery failures - #1129

Open
OskarEichler wants to merge 2 commits into
FormidableLabs:mainfrom
OskarEichler:codex/appauth-revocation-encoding
Open

fix: encode revocation requests and preserve discovery failures#1129
OskarEichler wants to merge 2 commits into
FormidableLabs:mainfrom
OskarEichler:codex/appauth-revocation-encoding

Conversation

@OskarEichler

Copy link
Copy Markdown

Fixes

Form-encode raw token/client values and OAuth Basic credential components, preserving reserved characters and Unicode. Treat an omitted Basic secret as empty, normalize one trailing issuer slash, reject failed discovery HTTP responses, and retain the original revocation network error as cause.

Breaking / observable changes

Send raw values, not pre-encoded strings. Reserved characters in Basic credentials now follow OAuth form encoding; providers relying on the old unescaped behavior may need adjustment. Revocation still returns the fetch Response and does not reinterpret HTTP failures as rejected promises; callers must inspect ok/status. Only discovery HTTP failures reject early. Existing sendClientId/includeBasicAuth defaults remain unchanged.

Verification

Actual-source JS controls cover reserved/Unicode/punctuation token round trips, Basic credential encoding, default omission of client_id/Basic headers, discovery URL and HTTP failure, and error cause preservation. RFC 6749 section 2.3.1 and RFC 7009 section 2.1 define the encoding.

Each patch was applied independently to upstream commit 6f9090ce1b991c0acc2a6f5dc8bea838deaf4f7a and passed its targeted external actual-source diagnostics or standalone type/lockfile check. The combined fixes pass 75 focused diagnostics. These use synthetic values, controlled native/bridge doubles and disposable filesystem projects, not real credentials.

Combined branch checks:

  • Existing Jest suite: 3 suites, 81 tests pass.
  • Root lint, demo lint, targeted App.tsx lint, demo TypeScript and standalone public-type checks pass.
  • Expo plugin TypeScript build passes. The optional lint:plugin command has a baseline tooling limitation: ESLint 6 does not find its TypeScript-only input.
  • Android Debug demo build passes with RN 0.79.2.
  • Unsigned iOS Simulator Debug demo build passes with RN 0.79.2.
  • Android and iOS production Metro demo bundles pass.
  • git diff --check passes.

No checked-in test/spec files were added, changed or disabled. The source changes are supported by external reproducible diagnostics because this audit's repository policy prohibits checked-in test edits. Live OAuth providers, physical-device/browser authentication and a full Expo native build were not exercised. React Doctor reports two warnings: the discovery response is explicitly guarded by response.ok === false, and the demo pending reset is inside finally; both paths are exercised by focused checks. No rules were suppressed.

Scope

  • docs/docs/usage/revoke.md
  • packages/react-native-app-auth/index.js
  • .changeset/appauth-revocation-encoding.md

Unrelated audit fixes are submitted separately. The separate iOS process-global OIDURLSessionProvider request-isolation issue is not claimed fixed by these changes.

@vercel

vercel Bot commented Aug 28, 2026

Copy link
Copy Markdown

@OskarEichler is attempting to deploy a commit to the Nearform Team on Vercel.

A member of the Team first needs to authorize it.

@changeset-bot

changeset-bot Bot commented Aug 28, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 54b6c83

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
Name Type
react-native-app-auth Patch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant