Skip to content

fix: avoid forced Microsoft OAuth consent - #51

Merged
calvinmclean merged 1 commit into
obot-platform:mainfrom
calvinmclean:fix/microsoft-consent-prompt
Sep 16, 2026
Merged

calvinmclean merged 1 commit into
obot-platform:mainfrom
calvinmclean:fix/microsoft-consent-prompt

Conversation

@calvinmclean

@calvinmclean calvinmclean commented Sep 15, 2026 •

Copy link
Copy Markdown
Member

Microsoft authorization requests inherited prompt=consent from the generic provider, which can trigger an unnecessary "Approval required" flow even when tenant-wide admin consent already exists.

This regressed in #13, when provider-specific authorization parameters were replaced with unconditional oauth2 options.

  • use prompt=select_account for Microsoft so users can choose another account without forcing consent
  • retain prompt=consent only for Google's authorization endpoint, preserving its refresh-token behavior
  • leave existing access_type=offline, requested scopes, and PKCE URL generation unchanged
  • add focused coverage for Microsoft, Google, and providers that require no prompt

@codecov-commenter

codecov-commenter commented Sep 15, 2026 •

Copy link
Copy Markdown

⚠️ Please install the 'codecov app svg image' to ensure uploads and comments are reliably processed by Codecov.

Codecov Report

❌ Patch coverage is 85.71429% with 2 lines in your changes missing coverage. Please review.

Files with missing lines Patch % Lines
pkg/providers/generic.go 85.71% 1 Missing and 1 partial ⚠️

📢 Thoughts on this report? Let us know!

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

The implementation matches the stated behavior and has focused regression coverage.

Pull request overview

Restricts Google-specific OAuth parameters to Google authorization endpoints, preventing forced Microsoft consent while preserving scopes and PKCE.

Changes:

  • Detect Google endpoints by hostname before adding offline consent options.
  • Add focused Microsoft, Google, generic-provider, and PKCE URL coverage.
File summaries
File Description
pkg/providers/generic.go Applies provider-aware authorization options.
pkg/providers/generic_test.go Verifies generated authorization parameters.
Review details
  • Files reviewed: 2/2 changed files
  • Comments generated: 0
  • Review effort level: Balanced

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@calvinmclean
calvinmclean marked this pull request as ready for review September 15, 2026 22:05
@calvinmclean
calvinmclean force-pushed the fix/microsoft-consent-prompt branch from 147ee89 to f6b2a56 Compare September 15, 2026 22:47
@calvinmclean
calvinmclean merged commit d3e588c into obot-platform:main Sep 16, 2026
3 checks passed
@calvinmclean
calvinmclean deleted the fix/microsoft-consent-prompt branch September 16, 2026 16:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants