Skip to content

feat: add --team to authorizations:info and authorizations:update - #3923

Closed
michaelmalave wants to merge 2 commits into
mainfrom
worker/gus-a3QEE000002hXIv2AM-2026-09-14-task-1
Closed

michaelmalave wants to merge 2 commits into
mainfrom
worker/gus-a3QEE000002hXIv2AM-2026-09-14-task-1

Conversation

@michaelmalave

@michaelmalave michaelmalave commented Sep 14, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Adds a --team option to heroku authorizations:info and heroku authorizations:update so an admin can inspect and modify an OAuth authorization owned by a team, not just their own personal tokens. Without the flag, both commands behave exactly as before.

  • Add --team (shared flags.team() helper) to authorizations:info and authorizations:update.
  • Route the GET (info) and PATCH (update) to /teams/{team}/oauth/authorizations/{id} when --team is set; keep the existing /oauth/authorizations/{id} path otherwise.
  • Add unit tests covering both the team and non-team paths for each command.

Type of Change

Feature Additions (minor semver update)

  • feat: Introduces a new feature to the codebase

Testing

Notes:
Automated: scoped authorizations unit suite is green (npm run test:ci:unit is chronically broken on cli main independent of this diff, so verification runs the scoped suite). Live smoke exercises the real team-authorizations endpoint that unit tests mock.

npx mocha --config .mocharc.json "test/unit/commands/authorizations/**/*.unit.test.ts"

Steps:

  1. git fetch origin worker/gus-a3QEE000002hXIv2AM-2026-09-14-task-1 && git checkout worker/gus-a3QEE000002hXIv2AM-2026-09-14-task-1
  2. npm ci && npm run build
  3. heroku login
  4. ./bin/run authorizations:info <AUTHORIZATION_ID> --team <TEAM> — Expect: prints the team-owned authorization
  5. ./bin/run authorizations:info <AUTHORIZATION_ID> --team <TEAM> --json — Expect: same, as JSON
  6. ./bin/run authorizations:update <AUTHORIZATION_ID> --team <TEAM> --description "smoke test" — Expect: updates the team-owned authorization
  7. ./bin/run authorizations:info <PERSONAL_AUTHORIZATION_ID> — Expect: unchanged personal-token behavior (no --team)

Additional Context

flags.team() (the shared @heroku-cli/command helper reused here, as in apps/members) carries an env-var default: --org → HEROKU_TEAM → HEROKU_ORGANIZATION. So a user with HEROKU_TEAM/HEROKU_ORGANIZATION exported will be routed to the team endpoint even without passing --team. This matches existing team-scoped commands; flagging it because these two commands did not previously have a team flag.

Related Issues

GUS work item: W-24132434

…W-24132434)

Adds a --team flag to both commands so they target a team-owned OAuth
authorization at /teams/${team}/oauth/authorizations/${id} instead of the
default /oauth/authorizations/${id} user path. Without --team, behavior is
unchanged. Unit tests cover both the team and non-team paths.
@michaelmalave
michaelmalave requested a review from a team as a code owner September 14, 2026 23:21
@michaelmalave
michaelmalave deployed to AcceptanceTests September 14, 2026 23:21 — with GitHub Actions Active
@michaelmalave
michaelmalave deployed to AcceptanceTests September 14, 2026 23:21 — with GitHub Actions Active
@michaelmalave
michaelmalave deployed to AcceptanceTests September 14, 2026 23:21 — with GitHub Actions Active
@michaelmalave
michaelmalave deployed to AcceptanceTests September 14, 2026 23:21 — with GitHub Actions Active
@michaelmalave michaelmalave changed the title Task 1: [CLI] authorizations info & update — read/modify a team-owned token with --team (W-24132434) feat: add --team to authorizations:info and authorizations:update Sep 14, 2026
…pdate

The team-owned authorizations API route (/teams/:team/oauth/authorizations)
is gated behind the 3.sdk API variant; without the Accept header the request
404s. Send SDK_HEADER on the --team path only and assert it in the team tests.
@michaelmalave

Copy link
Copy Markdown
Contributor Author

Closing: no CLI change required. There is no team-scoped GET/PATCH /teams/{team}/oauth/authorizations/{id} route — only the collection routes (list/create) are team-scoped. A team-owned token is read and updated by its UUID through the existing heroku authorizations:info <uuid> / heroku authorizations:update <uuid> commands: the Platform API resolves a team-owned token by UUID via find_team_authorization! and authorizes on the manage_tokens capability. So the capability this PR aimed to add already ships today with no code change; adding a --team flag here would route to an endpoint that 404s. Tracked under W-24132434 — see #3928 for the collection-level team work.

This branch was successfully deployed

1 active deployment
AcceptanceTests — f044af42 Deployed Sep 15, 2026 by michaelmalave via integration (20.x, ubuntu-latest) #9207
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant