Skip to content

Promote dev to main (reddit refresh via broker) - #64

Merged
JOY (JOY) merged 2 commits into
mainfrom
dev
Sep 25, 2026
Merged

JOY (JOY) merged 2 commits into
mainfrom
dev

Conversation

@JOY

@JOY JOY (JOY) commented Sep 25, 2026 •

Copy link
Copy Markdown

Promotion for prod deploy: #63 (Reddit token refresh through the dos.me broker, Reddit client creds dropped from repo env templates). Same reviewed diff, no new commits.


📌 TL;DR

This PR refactors the Reddit integration to route token refreshes through the dos.me OAuth broker, eliminating the need for REDDIT_CLIENT_ID and REDDIT_CLIENT_SECRET in the application environment. It updates the RedditProvider to use a new broker endpoint for refreshes and cleans up configuration files to remove the now-obsolete credentials.

🎯 Type of Change

  • 🚀 New feature
  • 🐛 Bugfix
  • 🧹 Refactor
  • ⚡ Performance
  • 📚 Documentation
  • ⚙️ CI / Configuration

🔍 Changes Walkthrough

File Summary of Changes
.env.example Removed REDDIT_CLIENT_ID and REDDIT_CLIENT_SECRET variables. Updated comments to clarify that both connect and refresh flows are fully brokered via dos.me.
docker-compose.yaml Removed REDDIT_CLIENT_ID and REDDIT_CLIENT_SECRET environment variable definitions from the service configuration.
libraries/nestjs-libraries/src/integrations/social/reddit.provider.ts Core Logic Update:
1. Replaced direct Reddit API calls in refreshToken with a call to the new broker endpoint (/oauth/reddit/refresh).
2. Added fetchRefreshBundle method to handle the broker refresh request.
3. Extracted parseBundle method to deduplicate response parsing logic between connect and refresh flows.
4. Implemented logic to preserve the existing refresh token if the broker does not return a new one (handling non-rotating refresh tokens).

📊 Architectural Flow

sequenceDiagram
    participant Crove as Crove App
    participant Broker as dos.me Broker
    participant Reddit as Reddit API

    Note over Crove, Broker: Token Refresh Flow (New)
    Crove->>Broker: POST /oauth/reddit/refresh<br/>(X-API-Key, refresh_token)
    Broker->>Reddit: POST /api/v1/access_token<br/>(Client Credentials + Refresh Token)
    Reddit-->>Broker: New Access Token
    Broker-->>Crove: Token Bundle (Access Token, Expires In)
    
    Note over Crove: Handle Non-Rotating Refresh Token
    alt Broker returns new refresh_token
        Crove->>Crove: Update stored refresh_token
    else Broker omits refresh_token
        Crove->>Crove: Keep existing refresh_token
    end

    Crove->>Reddit: GET /api/v1/me<br/>(Bearer New Access Token)
    Reddit-->>Crove: User Profile
Loading

…reds

refreshToken() now calls POST /oauth/reddit/refresh on the broker (same
ApiKeyGuard and token bundle shape as token-delivery) instead of running
the refresh grant against Reddit with REDDIT_CLIENT_ID/SECRET. When the
broker omits refreshToken (Reddit did not rotate), the stored token is
kept - a blank refresh token would break every later refresh.

With refresh brokered, no Reddit client credentials are needed in Crove
env at all: REDDIT_CLIENT_ID/SECRET are removed from .env.example and the
compose template. VM env cleanup happens at deploy time.
feat(reddit): refresh through the dos.me broker, drop Reddit client creds

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request migrates the Reddit token refresh flow to the dos.me OAuth broker, eliminating the need for Reddit client credentials in the application environment. The RedditProvider has been refactored to fetch refresh bundles from the broker and reuse a new parseBundle helper. To improve code maintainability, it is recommended to define a dedicated interface for the repeated token bundle structure.

Comment on lines +228 to +233
private async fetchRefreshBundle(refreshToken: string): Promise<{
accessToken: string;
refreshToken?: string;
expiresIn: number;
scopes: string[];
}> {

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

medium

To improve code clarity and maintainability, consider defining a dedicated interface for the token bundle structure. This structure is used as a return type in fetchTokenBundle, fetchRefreshBundle, and parseBundle, and defining it once would avoid repetition and make the code easier to read.

For example:

interface RedditBrokerBundle {
  accessToken: string;
  refreshToken?: string;
  expiresIn: number;
  scopes: string[];
}

You could then use Promise<RedditBrokerBundle> and RedditBrokerBundle in the respective method signatures.

@JOY
JOY (JOY) merged commit 500cd62 into main Sep 25, 2026
20 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant