Skip to content

feat: add --team to authorizations:create - #3926

Closed
michaelmalave wants to merge 2 commits into
mainfrom
worker/gus-a3QEE000002hXIv2AM-2026-09-14-task-4
Closed

michaelmalave wants to merge 2 commits into
mainfrom
worker/gus-a3QEE000002hXIv2AM-2026-09-14-task-4

Conversation

@michaelmalave

@michaelmalave michaelmalave commented Sep 14, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Adds a --team option to heroku authorizations:create so a user can create an OAuth authorization owned by a team instead of a personal token. Without the flag, the command creates a personal authorization exactly as before.

  • Add --team (shared flags.team() helper) to authorizations:create.
  • Route the create POST to /teams/{team}/oauth/authorizations when --team is set; keep the existing /oauth/authorizations path otherwise. Request body is unchanged.
  • Add a unit test covering the team create path.

Type of Change

Feature Additions (minor semver update)

  • feat: Introduces a new feature to the codebase

Testing

Notes:
Automated: scoped authorizations unit suite is green (npm run test:ci:unit is chronically broken on cli main independent of this diff, so verification runs the scoped suite). Existing flags (--description, --expires-in, --scope, --json, --short) are unaffected. Live smoke exercises the real team create endpoint that unit tests mock.

npx mocha --config .mocharc.json "test/unit/commands/authorizations/**/*.unit.test.ts"

Steps:

  1. git fetch origin worker/gus-a3QEE000002hXIv2AM-2026-09-14-task-4 && git checkout worker/gus-a3QEE000002hXIv2AM-2026-09-14-task-4
  2. npm ci && npm run build
  3. heroku login
  4. ./bin/run authorizations:create --team <TEAM> --description "smoke test" — Expect: creates a team-owned authorization
  5. ./bin/run authorizations:create --team <TEAM> --scope read --description "smoke scoped" — Expect: creates a scoped team-owned authorization
  6. ./bin/run authorizations:create --description "personal smoke" — Expect: unchanged behavior (personal authorization)

Additional Context

flags.team() (the shared @heroku-cli/command helper reused here, as in apps/members) carries an env-var default: --org → HEROKU_TEAM → HEROKU_ORGANIZATION. So a user with HEROKU_TEAM/HEROKU_ORGANIZATION exported will be routed to the team endpoint even without passing --team. This matches existing team-scoped commands; flagging it because this command did not previously have a team flag.

Related Issues

GUS work item: W-24132433

Adds --team to `heroku authorizations:create` so the created OAuth
authorization can be owned by a named team. When --team is set, the
command POSTs to /teams/${team}/oauth/authorizations (team value
encodeURIComponent'd); otherwise it keeps the existing
/oauth/authorizations user path. Existing flags (--description,
--expires-in, --scope, --json, --short) and the POST body are
unchanged.
@michaelmalave
michaelmalave requested a review from a team as a code owner September 14, 2026 23:22
@michaelmalave
michaelmalave deployed to AcceptanceTests September 14, 2026 23:22 — with GitHub Actions Active
@michaelmalave
michaelmalave deployed to AcceptanceTests September 14, 2026 23:22 — with GitHub Actions Active
@michaelmalave
michaelmalave deployed to AcceptanceTests September 14, 2026 23:22 — with GitHub Actions Active
@michaelmalave
michaelmalave deployed to AcceptanceTests September 14, 2026 23:22 — with GitHub Actions Active
@michaelmalave michaelmalave changed the title Task 4: [CLI] authorizations:create — create a team-owned token with --team (W-24132433) feat: add --team to authorizations:create Sep 14, 2026
The team-owned authorizations API route (/teams/:team/oauth/authorizations)
is gated behind the 3.sdk API variant; without the Accept header the request
404s. Send SDK_HEADER on the --team path only and assert it in the team test.
@michaelmalave

Copy link
Copy Markdown
Contributor Author

Superseded by #3928, which consolidates the team-owned-tokens CLI work (list + create --team) into a single PR against the latest main. The create --team change here is carried into #3928 unchanged. Closing in favor of the consolidated PR.

This branch was successfully deployed

1 active deployment
AcceptanceTests — dce4ae87 Deployed Sep 15, 2026 by michaelmalave via integration (20.x, ubuntu-latest) #9210
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant