Etsy setup: catch wrong app keys at setup, not at the first call - #881
Merged
Merged
Conversation
Etsy's sign-in succeeds with a wrong shared secret (its token exchange does not use it), so the guided setup said "is ready" and every call then failed with 403. Seen in the weekly stuck-users report: a secret pasted as "keystring:secret", the keystring pasted twice. - After the sign-in, the setup page already called the connector test; a refusal (auth_failed) now sends the user back to the keys with the provider's message instead of "is ready". - Etsy's Keystring and Shared secret get a pattern and a message saying what to paste (lowercase letters and digits, no colon). Checked against production: every working Etsy connector has a 24-character keystring and a 10- or 25-character secret; no value with a colon or space ever worked. - envVarMeta gains patternMessage; settings passed from the chat (setup_install_connector) are checked against the pattern too.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
From the weekly stuck-users report (5 Oct): the Etsy failures after the 3 Oct deploy are wrong app keys, not a bug in the request.
keystring:secret)shops_r(their Etsy app)The sign-in succeeded for all three: Etsy's token exchange does not check the shared secret, so the setup said "is ready" and the first call failed.
Changes
/openapi-pingwithx-api-key), but ignored its result. Anauth_failednow sends the user back to the keys with Etsy's message instead of "is ready".^[a-z0-9]{20,30}$, Shared secret^[a-z0-9]{8,32}$, each with a message on what to paste. Checked against production (shapes only): working connectors all have a 24-char lowercase keystring and a 10- or 25-char lowercase secret; no value with a colon, space or other symbol ever worked.envVarMeta.patternMessage(validator updated); settings passed from the chat viasetup_install_connectorare checked against the pattern too.Tests