Skip to content

feat: add --team to authorizations:revoke and authorizations:rotate - #3925

Closed
michaelmalave wants to merge 2 commits into
mainfrom
worker/gus-a3QEE000002hXIv2AM-2026-09-14-task-3
Closed

michaelmalave wants to merge 2 commits into
mainfrom
worker/gus-a3QEE000002hXIv2AM-2026-09-14-task-3

Conversation

@michaelmalave

@michaelmalave michaelmalave commented Sep 14, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Adds a --team option to heroku authorizations:revoke (and its authorizations:destroy alias) and heroku authorizations:rotate so an admin can revoke or rotate an OAuth authorization owned by a team. Without the flag, both commands behave exactly as before.

  • Add --team (shared flags.team() helper) to authorizations:revoke/:destroy and authorizations:rotate.
  • Route the revoke DELETE to /teams/{team}/oauth/authorizations/{id} when --team is set.
  • Route the rotate POST to /teams/{team}/oauth/authorizations/{id}/actions/regenerate-tokens when --team is set; keep the existing personal paths otherwise.
  • Add unit tests covering the team path for revoke and rotate.

Type of Change

Feature Additions (minor semver update)

  • feat: Introduces a new feature to the codebase

Testing

Notes:
Automated: scoped authorizations unit suite is green (npm run test:ci:unit is chronically broken on cli main independent of this diff, so verification runs the scoped suite). authorizations:destroy shares revoke.ts's class and is covered by the same tests. Live smoke exercises the real team endpoints that unit tests mock.

npx mocha --config .mocharc.json "test/unit/commands/authorizations/**/*.unit.test.ts"

Steps:

  1. git fetch origin worker/gus-a3QEE000002hXIv2AM-2026-09-14-task-3 && git checkout worker/gus-a3QEE000002hXIv2AM-2026-09-14-task-3
  2. npm ci && npm run build
  3. heroku login
  4. ./bin/run authorizations:rotate <AUTHORIZATION_ID> --team <TEAM> — Expect: rotates the team-owned authorization's tokens
  5. ./bin/run authorizations:revoke <AUTHORIZATION_ID> --team <TEAM> — Expect: revokes the team-owned authorization
  6. ./bin/run authorizations:revoke <PERSONAL_AUTHORIZATION_ID> — Expect: unchanged personal-token behavior (no --team)

Additional Context

flags.team() (the shared @heroku-cli/command helper reused here, as in apps/members) carries an env-var default: --org → HEROKU_TEAM → HEROKU_ORGANIZATION. So a user with HEROKU_TEAM/HEROKU_ORGANIZATION exported will be routed to the team endpoint even without passing --team. This matches existing team-scoped commands; flagging it because these commands did not previously have a team flag.

Related Issues

GUS work item: W-24132436

…otate (W-24132436)

When --team is set, revoke targets DELETE /teams/${team}/oauth/authorizations/${id}
and rotate targets POST /teams/${team}/oauth/authorizations/${id}/actions/regenerate-tokens.
Without --team, both commands keep their existing user-scoped paths. The --team flag
applies to both authorizations:revoke and its authorizations:destroy alias since they
share the same command class. Adds unit test coverage for both the team and non-team
paths on each command.
@michaelmalave
michaelmalave requested a review from a team as a code owner September 14, 2026 23:21
@michaelmalave
michaelmalave deployed to AcceptanceTests September 14, 2026 23:21 — with GitHub Actions Active
@michaelmalave
michaelmalave deployed to AcceptanceTests September 14, 2026 23:21 — with GitHub Actions Active
@michaelmalave
michaelmalave deployed to AcceptanceTests September 14, 2026 23:21 — with GitHub Actions Active
@michaelmalave
michaelmalave deployed to AcceptanceTests September 14, 2026 23:21 — with GitHub Actions Active
@michaelmalave michaelmalave changed the title Task 3: [CLI] authorizations revoke & rotate — revoke/rotate a team-owned token with --team (W-24132436) feat: add --team to authorizations:revoke and authorizations:rotate Sep 14, 2026
…/rotate

The team-owned authorizations API routes (/teams/:team/oauth/authorizations)
are gated behind the 3.sdk API variant; without the Accept header the request
404s. Send SDK_HEADER on the --team path only and assert it in the team tests.
@michaelmalave

Copy link
Copy Markdown
Contributor Author

Closing: no CLI change required. There is no team-scoped DELETE /teams/{team}/oauth/authorizations/{id} or .../actions/regenerate-tokens route — only the collection routes (list/create) are team-scoped. A team-owned token is revoked/rotated by its UUID through the existing heroku authorizations:revoke <uuid> (and :destroy) / heroku authorizations:rotate <uuid> commands: the Platform API resolves a team-owned token by UUID via find_team_authorization! and authorizes on the manage_tokens capability. So the capability this PR aimed to add already ships today with no code change; adding a --team flag here would route to an endpoint that 404s. Tracked under W-24132436 — see #3928 for the collection-level team work.

This branch was successfully deployed

1 active deployment
AcceptanceTests — 6c154f91 Deployed Sep 15, 2026 by michaelmalave via acceptance (20.x, ubuntu-latest) #9209
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant