From 5c32c32e951c891c3cfc6f73cd4fe00a369f9723 Mon Sep 17 00:00:00 2001 From: Mehrn0ush Date: Sat, 12 Sep 2026 02:45:51 +0800 Subject: [PATCH 1/2] Align /token responses with RFC 6749 cache and Basic encoding rules. Add Pragma: no-cache beside Cache-Control: no-store, and document form-urlencoded encoding of client credentials before Basic. Signed-off-by: Mehrn0ush --- auth/readme.md | 1 + spec/openapi.yaml | 13 ++++++++++++- 2 files changed, 13 insertions(+), 1 deletion(-) diff --git a/auth/readme.md b/auth/readme.md index 30b49ac..343ad7e 100644 --- a/auth/readme.md +++ b/auth/readme.md @@ -101,6 +101,7 @@ A successful response is the standard OAuth 2.0 token response (RFC 6749 section HTTP/1.1 200 OK Content-Type: application/json;charset=UTF-8 Cache-Control: no-store +Pragma: no-cache { "access_token": "2YotnFZFEjr1zCsicMWpAA", diff --git a/spec/openapi.yaml b/spec/openapi.yaml index 758804f..b0682b9 100644 --- a/spec/openapi.yaml +++ b/spec/openapi.yaml @@ -2149,6 +2149,13 @@ components: schema: type: string example: no-store + Pragma: + description: | + Servers shall set `no-cache` on token responses (RFC 6749 section 5.1), for + compatibility with HTTP/1.0 caches. + schema: + type: string + example: no-cache content: application/json: schema: @@ -2464,7 +2471,11 @@ components: description: | API key credentials, presented to `/token` only: the API key identifier as the user-id and the API key secret as the password (RFC 7617, RFC 6749 section - 2.3.1). Servers shall not accept API key credentials directly on other TEA + 2.3.1). Per RFC 6749 section 2.3.1, the identifier and secret are each encoded as + `application/x-www-form-urlencoded` before they are joined with a colon and + Base64-encoded for the `Authorization` header. Clients and servers shall apply + that encoding so credentials containing `:`, `@`, or other reserved characters + interoperate. Servers shall not accept API key credentials directly on other TEA endpoints; clients shall exchange them for an access token first. security: - bearerAuth: [] From 9987cd2e1bacd14ce29a91c22f016ce598565dfe Mon Sep 17 00:00:00 2001 From: Mehrn0ush Date: Sun, 13 Sep 2026 23:59:43 +0800 Subject: [PATCH 2/2] Drop Pragma from token responses RFC 9111 deprecates Pragma and OAuth 2.1 requires only Cache-Control: no-store. Keep the Basic form-urlencoded encoding clarification. Signed-off-by: Mehrn0ush --- auth/readme.md | 1 - spec/openapi.yaml | 7 ------- 2 files changed, 8 deletions(-) diff --git a/auth/readme.md b/auth/readme.md index 343ad7e..30b49ac 100644 --- a/auth/readme.md +++ b/auth/readme.md @@ -101,7 +101,6 @@ A successful response is the standard OAuth 2.0 token response (RFC 6749 section HTTP/1.1 200 OK Content-Type: application/json;charset=UTF-8 Cache-Control: no-store -Pragma: no-cache { "access_token": "2YotnFZFEjr1zCsicMWpAA", diff --git a/spec/openapi.yaml b/spec/openapi.yaml index b0682b9..8381d9e 100644 --- a/spec/openapi.yaml +++ b/spec/openapi.yaml @@ -2149,13 +2149,6 @@ components: schema: type: string example: no-store - Pragma: - description: | - Servers shall set `no-cache` on token responses (RFC 6749 section 5.1), for - compatibility with HTTP/1.0 caches. - schema: - type: string - example: no-cache content: application/json: schema: