Regenerate PHP SDK: restore OAuth auth on CRM clients - #628
Merged
Merged
Conversation
The previous codegen regen shipped ~54 CRM clients (Contacts, Companies, Deals, LineItems, Products, Quotes, Invoices, and all Crm/Objects/*) with no Authorization header, so every authenticated CRM call 401s. Root cause was in the generator: upstream CRM specs carry empty security and the only thing injecting oauth2 was per-client override files, which were incomplete/removed. Regenerated with api-clients' generic security injection fix (see api-clients "Inject default OAuth security so CRM clients keep auth on regen"), which restores the `Authorization: Bearer` block on all CRM request builders. Zero-auth Api classes drop from 69/159 to 12/160; the remaining 12 are OAuth token endpoints (public) and developer_hapikey clients (Webhooks, Automation Actions, CRM card/videoconferencing extensions), which correctly use a non-bearer scheme. Diff is auth restoration plus minor current-spec drift picked up by the regen (a few model field/enum updates and new Cms/SiteSearch files). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
ashleighliu
approved these changes
Oct 2, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
The previous codegen regen shipped ~54 CRM clients — Contacts, Companies, Deals, LineItems, Products, Quotes, Invoices, and every
Crm/Objects/*(Calls, Emails, Notes, Tasks, Meetings, Leads, …) — with noAuthorizationheader, so every authenticated CRM call returns401 Authentication credentials not found.Root cause is in the generator, not this repo: HubSpot's CRM object specs are served from upstream with
security: [], and the only thing injectingoauth2was per-client override files that were incomplete (Tickets had one and kept auth; Contacts' was deleted; the rest never had one).What
Regenerated the PHP SDK with the api-clients fix that injects default OAuth security for operations arriving with empty security (HubSpotEngineering/api-clients#380). This restores the
Authorization: Bearerblock on all CRM request builders.Verification
developer_hapikeyclients (Webhooks, Automation Actions, CRM card/videoconferencing extensions).php -lclean; no literaljson_encode($1)anywhere.The diff is auth restoration (57 files) plus minor current-spec drift the regen picked up (a few model field/enum updates, new
Cms/SiteSearchfiles). Nothing removed.Depends on HubSpotEngineering/api-clients#380.
🤖 Generated with Claude Code