feat: implement OAuth 2.0 Device Authorization Grant (RFC 8628)

Adds a third OAuthFlow variant (device_code) alongside the existing pkce and
client_credentials flows. Device flow enables OAuth for headless environments
where a browser-based callback listener isn't available — the user visits a
verification URL on any device and enters a short user_code.

- OAuthFlow::DeviceCode variant + serde 'device_code' string
- OAuthConfig fields: device_authorization_url, use_pkce_in_device_flow
- OAuthProvider trait: device_authorization_url() / use_pkce_in_device_flow()
- OpenAICompatibleOAuthProvider passes both through from config
- run_device_code_flow() polls the token endpoint per RFC 8628 §3.4–§3.5:
  handles authorization_pending, slow_down (+5s backoff), expired_token,
  access_denied, and unknown errors distinctly
- Sandbox-gated QR code display (via qrcode crate) — scanning with a phone
  is dramatically faster than copy-pasting the URL from a container
- Optional PKCE per draft-ietf-oauth-device-flow §5.4 (default off)
- run_oauth_flow and prepare_oauth_access_token dispatchers wire DeviceCode
  in; refresh path shared with PKCE since both flows produce refresh_tokens
This commit is contained in:
2026-07-20 15:21:32 -06:00
parent d13bd32fdf
commit 0fe430102a
2 changed files with 198 additions and 1 deletions
+8
View File
@@ -89,4 +89,12 @@ impl OAuthProvider for OpenAICompatibleOAuthProvider {
fn echo_pkce_in_token_exchange(&self) -> bool {
self.config.echo_pkce_in_token_exchange
}
fn device_authorization_url(&self) -> Option<&str> {
self.config.device_authorization_url.as_deref()
}
fn use_pkce_in_device_flow(&self) -> bool {
self.config.use_pkce_in_device_flow
}
}