fix(3cx): omit the bearer token on client-credentials login (#281)
Some checks are pending
Deploy API / Deploy API to dev (push) Waiting to run
Deploy API / Deploy API to prod (push) Waiting to run

A refresh was posting the expired access token to /connect/token, and 3CX answered 400. The login request now drops that header.
This commit is contained in:
Adam Moussa 2026-09-25 15:46:10 +00:00 • committed by GitHub
parent b3fa705d8c
commit 7b5009fb55
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
2 changed files with 9 additions and 2 deletions

View file

@ -137,6 +137,8 @@ class ThreeCXClient:
def _authenticate_oauth(self, client_id: str, client_secret: str):
"""Authenticate via OAuth2 client credentials (Enterprise license required).
API client must be created in 3CX Admin > Integrations > API."""
# Drop the session bearer. A refresh otherwise sends the expired
# access token to /connect/token, and 3CX answers 400.
resp = self._raw_request(
"POST",
f"{self.base_url}/connect/token",
@ -145,7 +147,10 @@ class ThreeCXClient:
"client_secret": client_secret,
"grant_type": "client_credentials",
},
headers={"Content-Type": "application/x-www-form-urlencoded"},
headers={
"Content-Type": "application/x-www-form-urlencoded",
"Authorization": None,
},
)
resp.raise_for_status()
body = resp.json()

View file

@ -263,7 +263,9 @@ def test_oauth_client_refreshes_expired_token():
queue = client.get_queue("801")
assert queue["Id"] == 83
assert client.session.headers["Authorization"] == "Bearer tok-2"
assert len(_token_posts()) == 2
posts = _token_posts()
assert len(posts) == 2
assert "Authorization" not in posts[1].request.headers
tcx._oauth_clients.clear()