feat: implement OAuth 2.0 Device Authorization Grant (RFC 8628)
Adds a third OAuthFlow variant (device_code) alongside the existing pkce and client_credentials flows. Device flow enables OAuth for headless environments where a browser-based callback listener isn't available — the user visits a verification URL on any device and enters a short user_code. - OAuthFlow::DeviceCode variant + serde 'device_code' string - OAuthConfig fields: device_authorization_url, use_pkce_in_device_flow - OAuthProvider trait: device_authorization_url() / use_pkce_in_device_flow() - OpenAICompatibleOAuthProvider passes both through from config - run_device_code_flow() polls the token endpoint per RFC 8628 §3.4–§3.5: handles authorization_pending, slow_down (+5s backoff), expired_token, access_denied, and unknown errors distinctly - Sandbox-gated QR code display (via qrcode crate) — scanning with a phone is dramatically faster than copy-pasting the URL from a container - Optional PKCE per draft-ietf-oauth-device-flow §5.4 (default off) - run_oauth_flow and prepare_oauth_access_token dispatchers wire DeviceCode in; refresh path shared with PKCE since both flows produce refresh_tokens
This commit is contained in:
@@ -89,4 +89,12 @@ impl OAuthProvider for OpenAICompatibleOAuthProvider {
|
||||
fn echo_pkce_in_token_exchange(&self) -> bool {
|
||||
self.config.echo_pkce_in_token_exchange
|
||||
}
|
||||
|
||||
fn device_authorization_url(&self) -> Option<&str> {
|
||||
self.config.device_authorization_url.as_deref()
|
||||
}
|
||||
|
||||
fn use_pkce_in_device_flow(&self) -> bool {
|
||||
self.config.use_pkce_in_device_flow
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user