Skip to content

fix: add Revenue OAuth authentication while preserving API-key workflows - #10

Merged
christopherjnelson merged 3 commits into
mainfrom
fix/revenue-auth-compatibility
Oct 7, 2026
Merged

christopherjnelson merged 3 commits into
mainfrom
fix/revenue-auth-compatibility

Conversation

@christopherjnelson

@christopherjnelson christopherjnelson commented Oct 7, 2026 •

Copy link
Copy Markdown
Member

Released Open Analytics v0.8.0 Revenue endpoints require a user principal with revenue:read and live owner membership; the existing site-bound API-key credential cannot satisfy that contract. Add optional native OAuth2 PKCE authentication for an already-registered public client, deriving authorize/token endpoints from one Base URL. Select Site ID on each Revenue node so one OAuth credential can serve multiple owned sites.

Keep API-key Analytics/Site behavior, saved Revenue operation identifiers and the legacy currency query unchanged. Restrict the native request/error callback to Revenue operations, retain safe HTTP status diagnostics with actionable hints, and let n8n handle token checks and refresh. Document released-source authentication and site-reporting-currency limits, separately from hosted behavior.

The README now includes a source-derived manual registration example for the anonymous public POST /v1/oauth/register endpoint: use the exact redirect URL shown by n8n, request only site:read revenue:read offline_access, and paste the returned client_id into the credential. The example has not been executed against the hosted service. Automatic registration remains future work. Upstream workspace issue #10 may change owner/site-selection semantics when released.

Validation: the combined package passed 86 tests across 10 files on Node 24.18.0 and 22.23.2 with npm 11.19.0. After refreshing the actual main checkout with npm ci, build, scanner source/built checks, package checks, isolated packed install, formatting, lint, strict typecheck and all 86 tests passed there on Node 24.18.0. The package contains 27 allowed files and loads one node/two credentials. Hosted OAuth login/refresh and editor behavior remain unverified; mocked tests do not establish live compatibility.

Template PR #9 was merged into main with merge commit 8914e2e. This PR now targets main and keeps the Revenue review limited to its 11 files. No version bump or release is included. Before release, actual n8n OAuth sign-in, token refresh and X-OA-Site behavior plus the hosted real-tag publish path still need qualification; the local v0.1.1 tag check is partial only.

Add a source-derived curl example using n8n's exact callback URL and
explain the returned client ID, anonymous registration and per-IP limits.
Keep owner authorization separate from client registration, document the
workspace compatibility risk, and retain pending live release checks.
@christopherjnelson
christopherjnelson marked this pull request as ready for review October 7, 2026 23:28
@christopherjnelson
christopherjnelson changed the base branch from chore/template-2.2-guidance to main October 7, 2026 23:29
@christopherjnelson
christopherjnelson merged commit ceb8d74 into main Oct 7, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant