Skip to content

feat: add --team to authorizations list - #3924

Closed
michaelmalave wants to merge 2 commits into
mainfrom
worker/gus-a3QEE000002hXIv2AM-2026-09-14-task-2
Closed

michaelmalave wants to merge 2 commits into
mainfrom
worker/gus-a3QEE000002hXIv2AM-2026-09-14-task-2

Conversation

@michaelmalave

@michaelmalave michaelmalave commented Sep 14, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Adds a --team option to heroku authorizations (the list command) so a user can list an OAuth authorizations belonging to a team instead of their personal tokens. Without the flag, the command lists personal authorizations exactly as before.

  • Add --team (shared flags.team() helper) to the authorizations list command.
  • Route the list GET to /teams/{team}/oauth/authorizations when --team is set; keep the existing /oauth/authorizations path otherwise.
  • Add unit tests covering both the team and non-team list paths.

Type of Change

Feature Additions (minor semver update)

  • feat: Introduces a new feature to the codebase

Testing

Notes:
Automated: scoped authorizations unit suite is green (npm run test:ci:unit is chronically broken on cli main independent of this diff, so verification runs the scoped suite). Live smoke exercises the real team-authorizations list endpoint that unit tests mock.

npx mocha --config .mocharc.json "test/unit/commands/authorizations/**/*.unit.test.ts"

Steps:

  1. git fetch origin worker/gus-a3QEE000002hXIv2AM-2026-09-14-task-2 && git checkout worker/gus-a3QEE000002hXIv2AM-2026-09-14-task-2
  2. npm ci && npm run build
  3. heroku login
  4. ./bin/run authorizations --team <TEAM> — Expect: lists the team's authorizations
  5. ./bin/run authorizations --team <TEAM> --json — Expect: same, as JSON
  6. ./bin/run authorizations — Expect: unchanged behavior (personal authorizations)

Additional Context

flags.team() (the shared @heroku-cli/command helper reused here, as in apps/members) carries an env-var default: --org → HEROKU_TEAM → HEROKU_ORGANIZATION. So a user with HEROKU_TEAM/HEROKU_ORGANIZATION exported will be routed to the team endpoint even without passing --team. This matches existing team-scoped commands; flagging it because this command did not previously have a team flag.

Related Issues

GUS work item: W-24132432

Adds an optional --team flag to `heroku authorizations` so it can list a
team's OAuth authorizations via GET /teams/:team/oauth/authorizations,
instead of the running user's tokens. Without --team, behavior is
unchanged. Reuses the existing table/JSON rendering and follows the
flags.team() convention already used by apps:index and usage:addons.
@michaelmalave
michaelmalave requested a review from a team as a code owner September 14, 2026 23:21
@michaelmalave
michaelmalave deployed to AcceptanceTests September 14, 2026 23:21 — with GitHub Actions Active
@michaelmalave
michaelmalave deployed to AcceptanceTests September 14, 2026 23:21 — with GitHub Actions Active
@michaelmalave
michaelmalave deployed to AcceptanceTests September 14, 2026 23:21 — with GitHub Actions Active
@michaelmalave
michaelmalave deployed to AcceptanceTests September 14, 2026 23:21 — with GitHub Actions Active
@michaelmalave michaelmalave changed the title Task 2: [CLI] authorizations — list a team's tokens with --team (W-24132432) feat: add --team to authorizations list Sep 14, 2026
The team-owned authorizations API route (/teams/:team/oauth/authorizations)
is gated behind the 3.sdk API variant; without the Accept header the request
404s. Send SDK_HEADER on the --team path only and assert it in the team tests.
@michaelmalave

Copy link
Copy Markdown
Contributor Author

Superseded by #3928, which consolidates the team-owned-tokens CLI work (list + create --team) into a single PR against the latest main. The list --team change here is carried into #3928 unchanged. Closing in favor of the consolidated PR.

This branch was successfully deployed

1 active deployment
AcceptanceTests — 0b79872d Deployed Sep 15, 2026 by michaelmalave via acceptance (22.x, ubuntu-latest) #9208
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant