Skip to content

[Feature]: Grantfox OAuth2 SSO integration #144

Description

@memplethee-lab

Feature Request

Problem Statement

Grant providers (such as Grantfox) need a secure, standard SSO/OAuth2 connection to allow projects and maintainers to link their accounts, authorize billing/grant access, and enable seamless grant receipt workflows. Currently the API lacks a first-class OAuth2 flow and token management for Grantfox, causing manual steps and friction for adopters.

Proposed Solution

Add a Grantfox OAuth2 SSO integration module that:

  • Implements OAuth2 Authorization Code flow with PKCE for web and native apps.
  • Exposes endpoints: /auth/grantfox/start, /auth/grantfox/callback, /auth/grantfox/refresh, /auth/grantfox/revoke.
  • Stores short-lived access tokens in-memory and refresh tokens encrypted at rest (using existing secrets manager), rotates refresh tokens on reuse, and supports token revocation.
  • Provides middleware to attach Grantfox identity to requests and a service to fetch grant entitlements and billing permissions.
  • Adds automated tests against Grantfox sandbox endpoints and an integration test that asserts full end-to-end authorization.

Acceptance criteria:

  • Endpoints implemented and documented in API spec.
  • PKCE-based Authorization Code flow works end-to-end in sandbox and returns a mapped internal user identity.
  • Token refresh and revocation work; refresh token rotation is implemented and tested.
  • Middleware exposes current Grantfox user and entitlements to service handlers.
  • Integration tests pass in CI using sandbox credentials (secrets stored in CI env vars).

Alternatives Considered

  • Using client credentials flow only (rejected: needs user consent and entitlements mapping).
  • Relying on manual token entry by maintainers (rejected: poor UX and insecure).

Additional Context

This feature is high-impact for the Grantfox and Stellar teams because it enables automated grant funding flows and reduces manual reconciliation.

Implementation Ideas (Optional)

  • Reuse existing auth abstractions; implement a new GrantfoxAuthProvider implementing an OAuth2Provider interface.
  • Use node-oauth2-client libraries and add adapter tests.

Would you be willing to contribute?

  • Yes, I'd like to submit a PR for this feature
  • I can help with testing
  • I can help with documentation
  • I'd rather let someone else work on this

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

GrantFox OSSIssue tracked in GrantFox OSSMaybe RewardedIssue may be eligible for a GrantFox rewardThird CampaignCampaign: Third CampaignenhancementNew feature or request

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions