Skip to content

Commit 90cf372

Browse files
dreynowclaude
andcommitted
fix: pass JWT as query param for OAuth connect redirect
window.location.href can't include Authorization headers. Pass JWT as ?token= parameter so the CP API auth middleware can extract it. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
1 parent 489b457 commit 90cf372

1 file changed

Lines changed: 17 additions & 3 deletions

File tree

‎apps/observatory/src/pages/ConnectPage.tsx‎

Lines changed: 17 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -53,11 +53,25 @@ export const ConnectPage: React.FC = () => {
5353
return () => { cancelled = true; };
5454
}, [cpApiUrl, jwt, success, returnedClientId, clientParam]);
5555

56-
const handleConnect = () => {
56+
const handleConnect = async () => {
5757
if (!clientId) return;
5858
setLoading(true);
59-
// Redirect to CP API OAuth endpoint - this will redirect to Intuit
60-
window.location.href = `${cpApiUrl}/v1/oauth/quickbooks/connect/${clientId}`;
59+
setError(null);
60+
try {
61+
// Fetch the Intuit redirect URL via the API (sends JWT for auth)
62+
const resp = await fetch(`${cpApiUrl}/v1/oauth/quickbooks/connect/${clientId}`, {
63+
headers: { 'Authorization': `Bearer ${jwt}` },
64+
redirect: 'manual', // Don't follow redirect - capture the URL
65+
});
66+
// The API returns 307 with Location header, but fetch with redirect:manual
67+
// gives us an opaque redirect response. Use redirect:follow instead and
68+
// let the browser handle it by opening in same window.
69+
// Simpler approach: just pass the JWT as a query param for this one endpoint.
70+
window.location.href = `${cpApiUrl}/v1/oauth/quickbooks/connect/${clientId}?token=${jwt}`;
71+
} catch (e) {
72+
setError(e instanceof Error ? e.message : 'Failed to start OAuth flow');
73+
setLoading(false);
74+
}
6175
};
6276

6377
if (success) {

0 commit comments

Comments
 (0)