pidge_client/auth/config.rs
1//! Compile-time constants and runtime overrides for the pidge OAuth app.
2
3/// The pidge app's `client_id` in Microsoft Entra.
4///
5/// Empty string means "not yet provisioned". Set by `scripts/register-pidge-app.sh`
6/// after registering the app in Entra. Until then, set the `PIDGE_CLIENT_ID` env var
7/// for development.
8pub const APP_CLIENT_ID: &str = "e49f90dc-c265-4392-b62f-b26704f9088f";
9
10/// Microsoft Graph delegated scopes pidge requests at sign-in.
11/// Locked in at app registration time; changing them later requires updating
12/// the Entra app permissions AND triggering incremental consent on existing
13/// accounts.
14///
15/// `openid` is included so Microsoft returns an `id_token` from the token
16/// endpoint; we decode it (no signature check) to extract the user's tenant
17/// for the Account record. `profile` is harmless and is what MSAL clients
18/// always request alongside `openid`.
19pub const SCOPES: &[&str] = &[
20 "openid",
21 "profile",
22 "offline_access",
23 "User.Read",
24 "Mail.ReadWrite",
25 "Mail.Send",
26 "Calendars.ReadWrite",
27];
28
29/// Microsoft identity platform endpoints (common = multi-tenant + personal MSA).
30pub const AUTHORITY: &str = "https://login.microsoftonline.com/common";
31pub const DEVICE_CODE_URL: &str = "https://login.microsoftonline.com/common/oauth2/v2.0/devicecode";
32pub const TOKEN_URL: &str = "https://login.microsoftonline.com/common/oauth2/v2.0/token";
33
34/// Microsoft Graph base URL.
35pub const GRAPH_BASE: &str = "https://graph.microsoft.com/v1.0";
36
37/// Resolved client_id: env var wins, otherwise the compile-time constant (if non-empty).
38pub fn client_id() -> Option<String> {
39 if let Ok(v) = std::env::var("PIDGE_CLIENT_ID")
40 && !v.is_empty()
41 {
42 return Some(v);
43 }
44 if APP_CLIENT_ID.is_empty() {
45 None
46 } else {
47 Some(APP_CLIENT_ID.to_string())
48 }
49}
50
51/// The space-separated scope string sent to Microsoft.
52pub fn scope_string() -> String {
53 SCOPES.join(" ")
54}