feat: refresh oauth tokens for mcp sessions

This commit is contained in:
lda
2026-06-13 05:44:00 +07:00 Verified
parent 87a7cf9e86
commit dc415b6410
4 changed files with 153 additions and 2 deletions
+56
View File
@@ -79,6 +79,62 @@ async def test_mcp_binder_refreshes_oauth_for_http() -> None:
assert len(refresher.calls) == 1
async def test_httpx_oauth_refresher_posts_refresh_token_grant(
monkeypatch: pytest.MonkeyPatch,
) -> None:
from pydantic import AnyUrl
from wf_sources_mcp import auth as mod
from wf_sources_mcp.auth import HttpxOAuthTokenRefresher
captured_posts: list[tuple[str, dict[str, str]]] = []
class _Response:
def raise_for_status(self) -> None:
return None
def json(self) -> dict[str, object]:
return {"access_token": "access-token", "expires_in": 3600}
class _Client:
async def __aenter__(self) -> "_Client":
return self
async def __aexit__(self, *args: object) -> None:
return None
async def post(self, url: str, *, data: dict[str, str]) -> _Response:
captured_posts.append((url, data))
return _Response()
monkeypatch.setattr(mod.httpx, "AsyncClient", _Client)
token = await HttpxOAuthTokenRefresher().refresh(
OAuthRefreshTokenAuth(
client_id="client",
client_secret="secret",
refresh_token="refresh",
token_url=AnyUrl("https://oauth2.googleapis.com/token"),
scopes=("scope.one", "scope.two"),
)
)
assert token.access_token == "access-token"
assert token.expires_in == 3600
assert captured_posts == [
(
"https://oauth2.googleapis.com/token",
{
"grant_type": "refresh_token",
"client_id": "client",
"client_secret": "secret",
"refresh_token": "refresh",
"scope": "scope.one scope.two",
},
)
]
async def test_mcp_binder_rejects_env_for_http() -> None:
binder = McpAuthBinder()
record = StoredAuthRecord(id="demo.auth", auth=EnvAuth(env={"TOKEN": "abc"}))