Skip to content

Commit 72bb7a5

Browse files
committed
fix(oauth): treat unauthorized_client as a terminal refresh error
1 parent 666b4d3 commit 72bb7a5

2 files changed

Lines changed: 9 additions & 0 deletions

File tree

‎apps/sim/lib/oauth/__tests__/terminal-errors.test.ts‎

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -49,6 +49,8 @@ describe('isTerminalRefreshError', () => {
4949
'invalid_client_id',
5050
'invalid_client',
5151
'bad_redirect_uri',
52+
'token_revoked',
53+
'unauthorized_client',
5254
])('returns true for %s', (code) => {
5355
expect(isTerminalRefreshError(code)).toBe(true)
5456
})

‎apps/sim/lib/oauth/terminal-errors.ts‎

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -4,6 +4,12 @@ import { getRedisClient } from '@/lib/core/config/redis'
44

55
const logger = createLogger('OAuthTerminalErrors')
66

7+
/**
8+
* Refresh error codes that no retry can recover from: the credential stays dead until
9+
* its owner reconnects. `unauthorized_client` is how Atlassian rejects a revoked or
10+
* rotated-out refresh token, and under RFC 6749 section 5.2 it otherwise means the
11+
* client may not use the refresh grant, which is equally persistent.
12+
*/
713
const TERMINAL_ERRORS = new Set<string>([
814
'invalid_refresh_token',
915
'bad_refresh_token',
@@ -14,6 +20,7 @@ const TERMINAL_ERRORS = new Set<string>([
1420
'invalid_client',
1521
'bad_redirect_uri',
1622
'token_revoked',
23+
'unauthorized_client',
1724
])
1825

1926
const DEAD_CACHE_TTL_SEC = 60 * 60

0 commit comments

Comments
 (0)