Skip to content

Regenerate PHP SDK: restore OAuth auth on CRM clients - #628

Merged
camden11 merged 1 commit into
masterfrom
cphalen/restore-crm-auth
Oct 2, 2026
Merged

camden11 merged 1 commit into
masterfrom
cphalen/restore-crm-auth

Conversation

@camden11

Copy link
Copy Markdown
Contributor

Why

The previous codegen regen shipped ~54 CRM clients — Contacts, Companies, Deals, LineItems, Products, Quotes, Invoices, and every Crm/Objects/* (Calls, Emails, Notes, Tasks, Meetings, Leads, …) — with no Authorization header, so every authenticated CRM call returns 401 Authentication credentials not found.

Root cause is in the generator, not this repo: HubSpot's CRM object specs are served from upstream with security: [], and the only thing injecting oauth2 was per-client override files that were incomplete (Tickets had one and kept auth; Contacts' was deleted; the rest never had one).

What

Regenerated the PHP SDK with the api-clients fix that injects default OAuth security for operations arriving with empty security (HubSpotEngineering/api-clients#380). This restores the Authorization: Bearer block on all CRM request builders.

Verification

  • Zero-auth Api classes: 69/159 → 12/160. The remaining 12 are legitimate — public OAuth token endpoints and developer_hapikey clients (Webhooks, Automation Actions, CRM card/videoconferencing extensions).
  • All previously-broken clients restored (Contacts, Companies, Deals, LineItems, Products, Quotes, Invoices, Calls, Emails, Notes, Tasks, Meetings).
  • php -l clean; no literal json_encode($1) anywhere.

The diff is auth restoration (57 files) plus minor current-spec drift the regen picked up (a few model field/enum updates, new Cms/SiteSearch files). Nothing removed.

Note: Webhooks / Automation Actions / CRM Extensions switched from OAuth-bearer to developer_hapikey in the prior regen (not this PR — regen reproduces them identically). Auth is still present, just a different scheme. Worth confirming separately if unintended.

Depends on HubSpotEngineering/api-clients#380.

🤖 Generated with Claude Code

The previous codegen regen shipped ~54 CRM clients (Contacts, Companies,
Deals, LineItems, Products, Quotes, Invoices, and all Crm/Objects/*) with
no Authorization header, so every authenticated CRM call 401s. Root cause
was in the generator: upstream CRM specs carry empty security and the only
thing injecting oauth2 was per-client override files, which were
incomplete/removed.

Regenerated with api-clients' generic security injection fix (see
api-clients "Inject default OAuth security so CRM clients keep auth on
regen"), which restores the `Authorization: Bearer` block on all CRM
request builders. Zero-auth Api classes drop from 69/159 to 12/160; the
remaining 12 are OAuth token endpoints (public) and developer_hapikey
clients (Webhooks, Automation Actions, CRM card/videoconferencing
extensions), which correctly use a non-bearer scheme.

Diff is auth restoration plus minor current-spec drift picked up by the
regen (a few model field/enum updates and new Cms/SiteSearch files).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@camden11
camden11 merged commit 0400ef8 into master Oct 2, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants