# docs: align comments with strict-200 OAuth check, fix interface wording

`f11b138`→[main](/content/gh/entireio/cli/commits/main/index.html)·

toothbrush·1mo ago·3 files·+6 added/-5 removed

Review nits from Copilot on #1402: PostOAuthToken treats anything but
200 as an error (RFC 6749 token-endpoint success is 200 only), so say
non-200 rather than non-2xx; and "slice of" read as a Go slice where
"subset" was meant.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

## Sessions

c5b9c3b810b5View transcript

[?\
Auth Refactor: Eliminate Static FallbacksClaude Code·Fable 5.\[1m\]·10 steps](/content/gh/entireio/cli/session/e6146684-ebfa-4f57-beff-34194cac8c2a#timeline-c5b9c3b810b5/index.html)

## Changes

3

- cmd/entire/cli

- Mrepo_mirror_probe.go+1/-1

- internal/entireclient/httputil

- Moauth.go+4/-3

- Moauth_test.go+1/-1

```
    161 unmodified lines

162
    163
    164
    165
    165
    166
    167
    168

161 unmodified lines

return true, NewSilentError(fmt.Errorf("mirror %s is suspended", mirrorID))
    // repoTokenSource is the slice of auth.RepoTokenSource the clone probe
    // repoTokenSource is the subset of auth.RepoTokenSource the clone probe
    // uses; an interface so tests can substitute a fake.
type repoTokenSource interface {
    Token(ctx context.Context, repoSlug, action string) (string, error)
    ```

Mcmd/entire/cli/repo_mirror_probe.go+1/-1

```
    58 unmodified lines

59
    60
    61
    62
    62
    63
    64
    65
    20 unmodified lines

86
    87
    88
    89
    90
    89
    90
    91
    92
    93
    94

58 unmodified lines

}

// OAuthError is returned by PostOAuthToken when the OAuth endpoint
    // responds with a non-2xx status. Callers can errors.As it to surface
    // responds with a non-200 status. Callers can errors.As it to surface
    // status-specific UX (e.g. a friendly 403 message) or branch on the
    // RFC 6749 error code.
type OAuthError struct {
    20 unmodified lines

// them on the other side — a raw '+'/'%xx' would round-trip to a different
    // value and fail invalid_client (matches core/api/token_endpoint.go).
    //
    // coreURL must already be trimmed of any trailing slash. A non-2xx
    // response is surfaced as *OAuthError; transport and decode failures
    // coreURL must already be trimmed of any trailing slash. A non-200
    // response is surfaced as *OAuthError (RFC 6749 defines token-endpoint
    // success as 200 only); transport and decode failures
    // are wrapped plain errors.
func PostOAuthToken(ctx context.Context, httpClient *http.Client, coreURL string, form url.Values) (accessToken string, expiresIn int, err error) {
    clientID := form.Get("client_id")
    ```

Minternal/entireclient/httputil/oauth.go+4/-3

```
    50 unmodified lines

51
    52
    53
    54
    54
    55
    56
    57

50 unmodified lines

assert.Empty(t, gotForm.Get("client_secret"), "client_secret must be dropped from the body")

// TestPostOAuthToken_ErrorCode pins that a non-2xx response surfaces as
    // TestPostOAuthToken_ErrorCode pins that a non-200 response surfaces as
    // *OAuthError with the RFC 6749 `error` code parsed from the body (empty for
    // non-JSON bodies), so callers can branch on e.g. invalid_target.
func TestPostOAuthToken_ErrorCode(t *testing.T) {
    ```

Minternal/entireclient/httputil/oauth_test.go+1/-1
