Conversation
…reds refreshToken() now calls POST /oauth/reddit/refresh on the broker (same ApiKeyGuard and token bundle shape as token-delivery) instead of running the refresh grant against Reddit with REDDIT_CLIENT_ID/SECRET. When the broker omits refreshToken (Reddit did not rotate), the stored token is kept - a blank refresh token would break every later refresh. With refresh brokered, no Reddit client credentials are needed in Crove env at all: REDDIT_CLIENT_ID/SECRET are removed from .env.example and the compose template. VM env cleanup happens at deploy time.
feat(reddit): refresh through the dos.me broker, drop Reddit client creds
There was a problem hiding this comment.
Code Review
This pull request migrates the Reddit token refresh flow to the dos.me OAuth broker, eliminating the need for Reddit client credentials in the application environment. The RedditProvider has been refactored to fetch refresh bundles from the broker and reuse a new parseBundle helper. To improve code maintainability, it is recommended to define a dedicated interface for the repeated token bundle structure.
| private async fetchRefreshBundle(refreshToken: string): Promise<{ | ||
| accessToken: string; | ||
| refreshToken?: string; | ||
| expiresIn: number; | ||
| scopes: string[]; | ||
| }> { |
There was a problem hiding this comment.
To improve code clarity and maintainability, consider defining a dedicated interface for the token bundle structure. This structure is used as a return type in fetchTokenBundle, fetchRefreshBundle, and parseBundle, and defining it once would avoid repetition and make the code easier to read.
For example:
interface RedditBrokerBundle {
accessToken: string;
refreshToken?: string;
expiresIn: number;
scopes: string[];
}You could then use Promise<RedditBrokerBundle> and RedditBrokerBundle in the respective method signatures.
Promotion for prod deploy: #63 (Reddit token refresh through the dos.me broker, Reddit client creds dropped from repo env templates). Same reviewed diff, no new commits.
📌 TL;DR
This PR refactors the Reddit integration to route token refreshes through the dos.me OAuth broker, eliminating the need for
REDDIT_CLIENT_IDandREDDIT_CLIENT_SECRETin the application environment. It updates theRedditProviderto use a new broker endpoint for refreshes and cleans up configuration files to remove the now-obsolete credentials.🎯 Type of Change
🔍 Changes Walkthrough
.env.exampleREDDIT_CLIENT_IDandREDDIT_CLIENT_SECRETvariables. Updated comments to clarify that both connect and refresh flows are fully brokered via dos.me.docker-compose.yamlREDDIT_CLIENT_IDandREDDIT_CLIENT_SECRETenvironment variable definitions from the service configuration.libraries/nestjs-libraries/src/integrations/social/reddit.provider.ts1. Replaced direct Reddit API calls in
refreshTokenwith a call to the new broker endpoint (/oauth/reddit/refresh).2. Added
fetchRefreshBundlemethod to handle the broker refresh request.3. Extracted
parseBundlemethod to deduplicate response parsing logic between connect and refresh flows.4. Implemented logic to preserve the existing refresh token if the broker does not return a new one (handling non-rotating refresh tokens).
📊 Architectural Flow
sequenceDiagram participant Crove as Crove App participant Broker as dos.me Broker participant Reddit as Reddit API Note over Crove, Broker: Token Refresh Flow (New) Crove->>Broker: POST /oauth/reddit/refresh<br/>(X-API-Key, refresh_token) Broker->>Reddit: POST /api/v1/access_token<br/>(Client Credentials + Refresh Token) Reddit-->>Broker: New Access Token Broker-->>Crove: Token Bundle (Access Token, Expires In) Note over Crove: Handle Non-Rotating Refresh Token alt Broker returns new refresh_token Crove->>Crove: Update stored refresh_token else Broker omits refresh_token Crove->>Crove: Keep existing refresh_token end Crove->>Reddit: GET /api/v1/me<br/>(Bearer New Access Token) Reddit-->>Crove: User Profile