feat(embedded-auth): Add POST /e/authorize Email OTP flow - #1292
Conversation
|
Important Review skippedAuto reviews are disabled on base/target branches other than the default branch. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Repository: auth0/Auth0.swift/.coderabbit.yaml Review profile: ASSERTIVE Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
d439050 to
a12fe54
Compare
89d0d25 to
c29c983
Compare
a12fe54 to
2c2517f
Compare
7df360a to
1483a56
Compare
1483a56 to
7dc6725
Compare
Implements the Embedded Login Discovery API (ROAD-5978 milestone 1). - Auth0.embeddedAuth() factory (explicit + plist-sourced overloads) - EmbeddedAuth protocol with discover(connection:) returning Request<DiscoveryResult, EmbeddedAuthError> - DiscoveryResult with typed LoginOption enum covering all 6 known grant types plus .unknown for forward-compatibility - Lenient decoding: unrecognized grant_type values surface as .unknown rather than throwing - EmbeddedAuthError with isFeatureDisabled / isInvalidRequest / isInvalidClient helpers - 43 Quick/Nimble tests covering all grant types, query params, error paths, and async API
…dCapability, AuthorizationCode types
… nextActions, isTooManyAttempts, isTooManyLogins to EmbeddedAuthError
…sionValidator, and factories
…hreading and full test suite
…s to ContentViewModel
0b507a6 to
55d25ab
Compare
…sitive data redaction, API surface - Remove redundant raw values from OtpType (redundant_string_enum_value lint) - Fix colon spacing in identifyEmail/identifyPhone/verifyOtp body dicts (colon lint) - Guard .keyboardType/.autocapitalization/.numberPad with #if !os(macOS) in ContentView - Remove challengeEmail(index:) — parameter was silently dropped; no-arg overload is the API - Add auth_session, authorization_code, otp to SensitiveDataRedactor.sensitiveKeys - Fix stale "Discovery API" doc on EmbeddedAuthError to "Authentication API" - Remove dead capturedBody(from:) test helper
07f397f to
eec046f
Compare
…thorization_code response Add AuthorizationCodeResponse Decodable wire type and use JSONDecoder in decodeAuthorizationCodeResponse. Also clear session on decode failure (200 without authorization_code is a terminal error — the flow cannot resume).
eec046f to
5917a45
Compare
9cfcf15 to
f2df198
Compare
sanchitmehtagit
left a comment
There was a problem hiding this comment.
Does this PR have any breaking changes if yes we should start the migration guide too
ed90dca to
b45432f
Compare
…ded-auth.md with beta
b45432f to
570de77
Compare
right now. It doesnot |
| if error.isInsufficientAuthorization, let newSession = error.info["auth_session"] as? String { | ||
| currentSession = newSession | ||
| } else if !error.isRetryable { | ||
| } else if error.isAccessDenied || error.isTooManyAttempts || error.isTooManyLogins { |
There was a problem hiding this comment.
could we have a function that wraps this ..
There was a problem hiding this comment.
instead of making changes here that function can be modified in future if needed
Changes
This PR adds the interactive Embedded Authorization loop (
POST /e/authorize, Email OTP delivery) and unifies it with the existing discovery client. Discovery and the authorize loop are now a single client: oneEmbeddedAuthprotocol, oneAuth0EmbeddedAuthimplementation, and oneembeddedAuth(...)factory handle bothGET /e/discoveryandPOST /e/authorize.API added to
EmbeddedAuthauthorize(connection:capabilities:scope:audience:)/authorize(connection:)— starts the multi-step flow;connectionis required (omitting it yieldsinvalid_requestserver-side)identify(_:)— submits the user's email address as the identifier and identifierTypechallengeEmail(index:)— triggers email OTP delivery for the givennext-array indexverifyOtp(_:type:)— submits the OTP (type: .oobfor email/SMS,.totpfor authenticator) and, on success, internally exchanges the authorization code forCredentialsand returns them directly; callers never handle the raw code,code_verifier, orredirect_uriDemo app (
App/)Full end-to-end SwiftUI flow across iOS, macOS, and tvOS:
authorize(connection:)discover()and listsLoginOptionvaluesnextActions: [identifyEmail]→ emailTextField→identify(_:)nextActions: [challengeEmail]→ masked destination shown →challengeEmail(index:)nextActions: [verifyOTP]→ OTPTextField→verifyOtp(_:type:)Checklist
auth_session/authorization_code/otpredacted in logs; never exposed to callersaccessToken/idToken/refreshTokennever loggedasync throwsAPIs providedpublicmembers