Files
sure/app/models/snaptrade_item/provided.rb
Max Barbare 51c93649da feat(snaptrade): replace device-flow OAuth with authorization-code + PKCE flow (#2747)
* feat(snaptrade): replace device-flow OAuth with authorization-code + PKCE flow

Squashed from 16 commits on snaptrade-oauth-apps for a clean rebase onto
current upstream/main ahead of opening a PR.

* fix(snaptrade): address PR #2747 review feedback on OAuth PKCE flow

- Remove unreachable dead-code guard in import_latest_snaptrade_data
- Guard apply_oauth_tokens! against a malformed payload missing access_token
- Wrap token endpoint network errors in ApiError and retry like data calls
- Remove unused Provider::Snaptrade#revoke_token! instance method
- Preserve return_to/accountable_type through the SnapTrade portal callback
  so the account-linking flow no longer drops users back to accounts_path
- Show the real absolute OAuth callback URL in self-hosted setup instructions
- Refresh brakeman.ignore fingerprint for the connect redirect after the
  return_to/accountable_type params were added

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Y8SCCmKX6RphB5E73WSUQQ

* fix(snaptrade): don't retry non-idempotent OAuth/API requests

CodeRabbit flagged that Provider::Snaptrade retried OAuth token
exchanges/refreshes and all API POST/DELETE calls (get_connection_url,
delete_connection) after timeouts/connection failures. If the response
is lost after SnapTrade already consumed a single-use auth code,
rotated the refresh token, or applied a POST/DELETE, replaying the
request either fails with invalid_grant on a token that actually
succeeded, or risks duplicate side effects. Retries are now limited to
GET requests; OAuth token requests and non-GET API calls translate a
network failure straight into an ApiError without replay.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01NrrGkgSBEqhjjBmmH1fcXL

* fix(snaptrade): stop querying non-deterministically encrypted token via empty-string compare

CodeRabbit flagged that the syncable scope's where.not(oauth_access_token:
[nil, ""]) re-encrypts "" with a random IV on every query, so the ""
comparison can never match a stored ciphertext and is a silent no-op.
No code path ever persists oauth_access_token as "" (only nil or a real
token via apply_oauth_tokens!), so the exclusion is unnecessary --
narrowed the scope to a plain NULL check, which encryption handles
transparently since nil is never encrypted.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01NrrGkgSBEqhjjBmmH1fcXL

---------

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-24 22:45:44 +02:00

58 lines
1.6 KiB
Ruby

module SnaptradeItem::Provided
extend ActiveSupport::Concern
included do
before_destroy :revoke_oauth_tokens
end
def snaptrade_provider
return nil unless oauth_configured?
Provider::Snaptrade.new(self)
end
# Exchange an authorization code for tokens and mark the item usable.
def complete_oauth_exchange!(code:, redirect_uri:, code_verifier:)
payload = Provider::Snaptrade.exchange_code(
code: code,
redirect_uri: redirect_uri,
code_verifier: code_verifier
)
apply_oauth_tokens!(payload)
update!(status: :good)
payload
end
# Get the connection portal URL for linking brokerages
def connection_portal_url(redirect_url:, broker: nil)
provider = snaptrade_provider
raise StandardError, "SnapTrade is not authorized" unless provider
provider.get_connection_url(redirect_url: redirect_url, broker: broker)
end
# Fetch all brokerage connections from SnapTrade API. Returns Array<Hash>.
def fetch_connections
provider = snaptrade_provider
return [] unless provider
provider.list_connections
rescue Provider::Snaptrade::ApiError => e
Rails.logger.error "SnaptradeItem #{id} - Failed to list connections: #{e.message}"
raise
end
private
# Best-effort token revocation when the item is destroyed.
def revoke_oauth_tokens
token = oauth_refresh_token.presence || oauth_access_token
return if token.blank?
Provider::Snaptrade.revoke_token(token: token)
rescue => e
# Never block deletion on revocation failures
Rails.logger.warn "SnapTrade: Failed to revoke tokens for item #{id}: #{e.class} - #{e.message}"
end
end