POA#464986: OAuth-documentatie bijwerken voor RFC-conforme token- en authorize-endpoints - #184
Draft
Pieter-Henk (maui1911) wants to merge 4 commits into
Draft
Pieter-Henk (maui1911) wants to merge 4 commits into
Pieter-Henk (maui1911) wants to merge 4 commits into
Conversation
…ndpoint Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…ndpoint Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Aanleiding
De OAuth-endpoints van de Connector Service zijn RFC-conform gemaakt in AFASSoftware/profit#26798 (POA#464986). Een klant liep vast omdat
expires_inals string werd geleverd. Daarnaast verandert het gedrag van het token- en authorize-endpoint op een aantal punten die integratoren moeten weten. Deze PR werktmarkdownpages/profit/nl/authentication.mden de Engelse versie daarop bij.Pas mergen als de release met profit#26798 in productie staat. Tot die tijd beschrijft deze tekst gedrag dat de omgevingen nog niet hebben, zoals de Basic-header. Zet vlak voor het mergen de
datein de frontmatter van beide bestanden op de datum van die dag: de check "Validate markdownpages frontmatter date" eist de datum van de dag waarop hij draait.Wijzigingen
Client credentials flow
refresh_tokenmeer (wasnull); de tekst en het voorbeeld zijn aangepast.expires_inwordt beschreven als getal.-u "<CLIENT_ID>:<CLIENT_SECRET>").Authorization code flow
redirect_urimoet exact overeenkomen; alleen schema en host mogen in hoofdletters afwijken, en een fragment wordt geweigerd.code_challenge_methodisS256(was een placeholder).codeen, als die is meegestuurd,state; de login moet binnen 10 minuten zijn afgerond.redirect_uriletterlijk gelijk zijn; de code is eenmalig bruikbaar.errorenstateterugkomt en wanneer als foutpagina.Nieuwe kopjes
POSTmetapplication/x-www-form-urlencoded, anders "Invalid HTTP request for token endpoint". Elke parameter één keer.WWW-Authenticate: Bearer error="invalid_token".Elk punt is gecontroleerd tegen de code van profit#26798 en een lokale doorloop met curl.
🤖 Generated with Claude Code