Skip to content

[connectors] Phase 2: generic OAuth2 handler (manifest-driven authorize/callback/refresh) #147

Description

@serge-ivo

Fold the hand-rolled Drive/Gmail/GitHub OAuth flows into one manifest-driven handler keyed by connector id (authorize + callback + refresh from auth config; refresh token envelope-encrypted; secretRef resolved server-side). Unlocks Slack/Sheets/Notion as manifests-only. Part of #143.

Metadata

Metadata

Assignees

No one assigned

    Labels

    backendBackend / Worker / API workconnectorsConnector + tool frameworksecuritySecurity hardening / audit finding

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions