You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Adds comprehensive TypeScript types throughout the OAuth package and eliminates all 44 occurrences of any type. This establishes a strong type foundation for the package and prepares it for ESLint config
Changes Made
Created src/types.ts: Centralized all shared type definitions
Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.
This PR includes no changesets
When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types
ArtieReus
changed the title
feat(oauth): convert package to use correct types
feat(oauth): add comprehensive TypeScript types and eliminate all 'any' usage
Sep 29, 2026
requestParams now rejects numeric and boolean values such as { max_age: 0 }, although createOidcRequest stringifies each value when building the URL and earlier callers could pass them. Widen this field and the matching CreateOidcRequestParams.requestParams to accept string | number | boolean values so existing, working requests still type-check.
Clone URL before appending the OIDC discovery path
packages/oauth/src/oidcConfig.ts:11
getOidcConfig now explicitly accepts a URL, but line 23 uses that same object and line 26 appends the discovery path to its pathname. After one call, the caller's URL is changed; calling again with it misses the original cache entry and fetches a path with /.well-known/openid-configuration appended twice. Clone the URL before changing its pathname and cover reuse of a URL instance in the config tests.
Remove any cast and type-check the PKCE callback
packages/oauth/src/oidcState.ts:15
The new PKCE callback type does not remove the (getPkceImport as any) cast on line 12, so this source file still contains an explicit any despite the PR's stated goal. That cast also bypasses checking the resolved callable. Narrow the CommonJS/ESM export from unknown, verify it is a function, and give that function the PKCE signature.
Preview removed because the pull request was closed.
2026-09-29 16:32 UTC
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
greenhouse-pr-buildSet this label to create a preview image which will automatically set the `greenhouse-pr-preview`
4 participants
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Adds comprehensive TypeScript types throughout the OAuth package and eliminates all 44 occurrences of
anytype. This establishes a strong type foundation for the package and prepares it for ESLint configChanges Made
Created
src/types.ts: Centralized all shared type definitionsFlowType,OidcConfig,IdTokenData,ParsedTokenData,AuthDataSessionStatediscriminated union for type-safe state managementTokenSessionStatefor tokenSession's simpler state modelOidcStateData,TokenResponse,FlowResponsefor OAuth flowssrc/utils.ts: Typed all utility functions (encodeBase64Json,decodeBase64Json,paramsToUrl)src/tokenHelpers.ts: Added proper return types and fixed array map callbackssrc/oidcConfig.ts: Fixed async bug (config: await r.json()) and added typessrc/oidcState.ts: Typed state management and PKCE callbackssrc/implicitFlow.ts&src/codeFlow.ts: Typed all OAuth flow functionssrc/oidcSession.ts: Most comprehensive changesSessionStateUpdateunion type for type-safe partial updatesreceiveNewDatato explicitly handle auth data presenceflowTypeinstead offlowType: flowType)src/tokenSession.ts: Aligned with shared types from types.tssrc/mockedSession.ts: Uses sharedSessionStateand interfacessrc/index.ts: Exported all public types for consumers includingTokenSessionStateRelated Issues
Screenshots (if applicable)
N/A - Type-only changes, no visual impact
Testing Instructions
pnpm icd packages/oauthpnpm typecheck- should pass with no errorspnpm lint- should pass with no errorspnpm test- all 85 tests should passpnpm build- should build successfullyChecklist
PR Manifesto
Review the PR Manifesto for best practises.