@@ -9,6 +9,10 @@ export const OAUTH_CLIENT_ID_METADATA_DOCUMENT_TARGET_PATH_PREFIX =
99export const OAUTH_CLIENT_ID_METADATA_DOCUMENT_DEFAULT_TARGET = "default" as const ;
1010export const OAUTH_CLIENT_ID_METADATA_DOCUMENT_LOCAL_TARGET = "local" as const ;
1111
12+ // Keep CIMD aligned with DCR: providers may reject `offline_access` unless the
13+ // client declares that it can use the refresh-token grant.
14+ const OAUTH_CLIENT_GRANT_TYPES = [ "authorization_code" , "refresh_token" ] as const ;
15+
1216type MetadataTarget =
1317 | typeof OAUTH_CLIENT_ID_METADATA_DOCUMENT_DEFAULT_TARGET
1418 | typeof OAUTH_CLIENT_ID_METADATA_DOCUMENT_LOCAL_TARGET
@@ -19,7 +23,7 @@ interface OAuthClientIdMetadataDocument {
1923 readonly client_name : string ;
2024 readonly client_uri : string ;
2125 readonly redirect_uris : readonly string [ ] ;
22- readonly grant_types : readonly [ "authorization_code" ] ;
26+ readonly grant_types : typeof OAUTH_CLIENT_GRANT_TYPES ;
2327 readonly response_types : readonly [ "code" ] ;
2428 readonly token_endpoint_auth_method : "none" ;
2529 readonly application_type : "web" | "native" ;
@@ -129,7 +133,7 @@ export const oauthClientIdMetadataDocumentFromRequest = ({
129133 client_name : "Executor Local" ,
130134 client_uri : url . origin ,
131135 redirect_uris : localLoopbackRedirectUris ( mountPrefix ) ,
132- grant_types : [ "authorization_code" ] ,
136+ grant_types : OAUTH_CLIENT_GRANT_TYPES ,
133137 response_types : [ "code" ] ,
134138 token_endpoint_auth_method : "none" ,
135139 application_type : "native" ,
@@ -150,7 +154,7 @@ export const oauthClientIdMetadataDocumentFromRequest = ({
150154 client_name : "Executor" ,
151155 client_uri : url . origin ,
152156 redirect_uris : [ redirectUri . toString ( ) ] ,
153- grant_types : [ "authorization_code" ] ,
157+ grant_types : OAUTH_CLIENT_GRANT_TYPES ,
154158 response_types : [ "code" ] ,
155159 token_endpoint_auth_method : "none" ,
156160 application_type : "web" ,
0 commit comments