Handle invalid OAuth token validation responses#8
Merged
altaywtf merged 1 commit intoputdotio:masterfrom May 8, 2026
Merged
Conversation
110fa15 to
70434df
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
Treat
ValidateTokenresponses withresult:falseas invalid tokens instead of returning(nil, nil). Also returnErrInvalidTokenwhen the validation response has nouser_id.Why
The Put.io OAuth validation endpoint can return HTTP 200 with a payload like:
{"result":false,"token_id":null,"token_scope":null,"user_id":null}The current client only decodes
user_id, so callers see(nil, nil)and have to guess whether the token is invalid or the response is malformed. Returning a sentinel error gives callers a reliable path for stale/invalid tokens.Compatibility
The
ValidateTokensignature is unchanged. Valid responses still return the user ID. Invalid or missing-user responses now returnErrInvalidTokeninstead of(nil, nil).Tests
go test ./...