feat: oauth support: add oauth2 related classes#225
Merged
kalenkevich merged 7 commits intomainfrom Apr 1, 2026
Merged
Conversation
ScottMansfield
approved these changes
Apr 1, 2026
Member
ScottMansfield
left a comment
There was a problem hiding this comment.
LGTM with some comments
9a2145c to
d22a0d1
Compare
2aec29d to
14b0376
Compare
- PKCE (Proof Key for Code Exchange) - CSRF (State Parameter) - Mix-Up attacks - SSRF via Discovery - Token Storage (XSS)
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
This PR introduces the core infrastructure for OAuth2 support in the TypeScript ADK. It implements metadata discovery (RFC 8414 and RFC 9728), credential exchange, and token refreshing, along with comprehensive unit tests for each component.
These additions lay the groundwork for full OAuth2 authentication flows within the ADK.
Changes Made
Core Components
oauth2_discovery.ts
OAuth2DiscoveryManager: Implements OAuth 2.0 Authorization Server Metadata (RFC 8414) and OAuth 2.0 Protected Resource Metadata (RFC 9728) discovery..well-knownendpoints for both Authorization Servers and Protected Resources.issuerorresourcematches the target URL, defending against mix-up attacks.oauth2_credential_exchanger.ts
OAuth2CredentialExchanger: Handles exchangingclient_credentialsandauthorization_codefor access tokens.AuthCredentialobjects.oauth2_credential_refresher.ts
OAuth2CredentialRefresher: Automatically checks for token expiration and refreshes OAuth2 credentials using refresh tokens.oauth2_utils.ts