Skip to content

Add an Output io.Writer so auth flow output can be redirected - #92

Merged
wesleymccollam merged 3 commits into
v1300from
reviseOauthGrantHandlers
Sep 10, 2026
Merged

wesleymccollam merged 3 commits into
v1300from
reviseOauthGrantHandlers

Conversation

@wesleymccollam

Copy link
Copy Markdown
Contributor

Summary

Adds an Output io.Writer field to the authorization-code and device-code configs so consumers can route (or silence, via io.Discard) the progress messages the default handlers write, instead of having that output locked to stdout. Hand-rolled handler implementations continue to own their output completely whenever one is supplied.

Changes

  • config/config_oauth.go: new Output field on the authorization-code config
  • config/config_oauth_test.go: coverage for redirecting output and for io.Discard
  • README.md: document the new field

Testing

  • go test ./...
  • go vet ./...

…figs so

consumers can redirect (or silence, via io.Discard) the progress messages the
default handlers print, instead of having output hardwired to stdout. Custom
handlers still own their output entirely whenever one is supplied.
Comment thread config/authorization_code.go Outdated
Comment thread config/hooks.go Outdated
Comment thread config/hooks_test.go Outdated
)

// A non-http(s) scheme is used for every URL below so that browser.Open rejects it during URL
// validation, before it would otherwise shell out to open a real browser window.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Our pingcli tests do this (opening a browser), can we follow this same pattern there to avoid that?

Also, it would be best to point these at a localhost/127.0.0.1 instead of a domain we don't own

- Invert the Output default: the SDK no longer prints to stdout at all —
  progress output is opt-in. nil/omitted Output disables it entirely;
  os.Stdout (via the With*Output builders or *To(w)) reproduces the
  interactive v1300.1.0 behavior.

- Point every auth-flow test URL at 127.0.0.1 instead of external
  domains, and state in the test comments (pingcli-style) that these
  tests do NOT open browsers — browser.Open rejects the non-http(s)
  scheme during validation, before any browser could launch.
The extension points have no consumers: the only repo requiring this SDK
(terraform-provider-pingfederate) pins v1300.0.0, which predates them.
Follow-up to the review feedback — with output now opt-in via Output, the
override is redundant and unused.

The flows now always use the default handler through *To(output). Tests
that relied on a failing handler to exercise flow paths now occupy the
default redirect port instead, so they fail at callback-server startup
before the browser step.
@wesleymccollam
wesleymccollam merged commit 0e5a74a into v1300 Sep 10, 2026
6 checks passed
@wesleymccollam
wesleymccollam deleted the reviseOauthGrantHandlers branch September 10, 2026 16:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants