Repository navigation
fix: add Revenue OAuth authentication while preserving API-key workflows - #10
Merged
Merged
Conversation
Add a source-derived curl example using n8n's exact callback URL and explain the returned client ID, anonymous registration and per-IP limits. Keep owner authorization separate from client registration, document the workspace compatibility risk, and retain pending live release checks.
christopherjnelson
marked this pull request as ready for review
October 7, 2026 23:28
christopherjnelson
changed the base branch from
chore/template-2.2-guidance
to
main
October 7, 2026 23:29
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Released Open Analytics v0.8.0 Revenue endpoints require a user principal with revenue:read and live owner membership; the existing site-bound API-key credential cannot satisfy that contract. Add optional native OAuth2 PKCE authentication for an already-registered public client, deriving authorize/token endpoints from one Base URL. Select Site ID on each Revenue node so one OAuth credential can serve multiple owned sites.
Keep API-key Analytics/Site behavior, saved Revenue operation identifiers and the legacy currency query unchanged. Restrict the native request/error callback to Revenue operations, retain safe HTTP status diagnostics with actionable hints, and let n8n handle token checks and refresh. Document released-source authentication and site-reporting-currency limits, separately from hosted behavior.
The README now includes a source-derived manual registration example for the anonymous public POST /v1/oauth/register endpoint: use the exact redirect URL shown by n8n, request only site:read revenue:read offline_access, and paste the returned client_id into the credential. The example has not been executed against the hosted service. Automatic registration remains future work. Upstream workspace issue #10 may change owner/site-selection semantics when released.
Validation: the combined package passed 86 tests across 10 files on Node 24.18.0 and 22.23.2 with npm 11.19.0. After refreshing the actual main checkout with npm ci, build, scanner source/built checks, package checks, isolated packed install, formatting, lint, strict typecheck and all 86 tests passed there on Node 24.18.0. The package contains 27 allowed files and loads one node/two credentials. Hosted OAuth login/refresh and editor behavior remain unverified; mocked tests do not establish live compatibility.
Template PR #9 was merged into main with merge commit 8914e2e. This PR now targets main and keeps the Revenue review limited to its 11 files. No version bump or release is included. Before release, actual n8n OAuth sign-in, token refresh and X-OA-Site behavior plus the hosted real-tag publish path still need qualification; the local v0.1.1 tag check is partial only.