Repository navigation
Remove JSONP support from token revocation - #951
Merged
Merged
Conversation
JSONP was useful in the past for cross-origin requests but has been superseded by CORS browser protections. This change removes the outdated JSONP functionality. Breaking changes: - Remove enable_jsonp parameter from RevocationEndpoint - Remove callback parameter from prepare_token_revocation_request - Remove JSONP documentation and examples - Remove JSONP tests The token revocation endpoint now returns empty response bodies on success instead of JSONP-wrapped responses.
Contributor
There was a problem hiding this comment.
Pull request overview
This PR removes JSONP support from the OAuth 2.0 token revocation endpoint and client-side request preparation, aligning revocation flows with modern CORS-based cross-origin patterns and reducing exposure to JSONP-related risks.
Changes:
- Removed
enable_jsonpfromRevocationEndpointand stopped emitting JSONP-wrapped responses. - Removed explicit
callbacksupport fromprepare_token_revocation_request(client API and parameter helper) and deleted JSONP-specific tests. - Added a WIP changelog entry documenting the breaking change.
Reviewed changes
Copilot reviewed 6 out of 6 changed files in this pull request and generated 2 comments.
Show a summary per file
| File | Description |
|---|---|
tests/oauth2/rfc6749/endpoints/test_revocation_endpoint.py |
Removes the JSONP callback revocation response test. |
tests/oauth2/rfc6749/clients/test_base.py |
Removes JSONP-style revocation request preparation test coverage. |
oauthlib/oauth2/rfc6749/parameters.py |
Drops explicit callback param and always encodes params into the request body. |
oauthlib/oauth2/rfc6749/endpoints/revocation.py |
Removes JSONP response wrapping and simplifies success response body to empty string. |
oauthlib/oauth2/rfc6749/clients/base.py |
Removes JSONP documentation and the explicit callback arg from the client API. |
CHANGELOG.rst |
Documents the breaking removal of JSONP support under WIP. |
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
Co-authored-by: Copilot Autofix powered by AI <[email protected]>
Prevent callback from being accepted via kwargs in prepare_token_revocation_request, and add a regression test to ensure callback now raises TypeError. Co-authored-by: Copilot <[email protected]>
auvipy
added a commit
that referenced
this pull request
Sep 28, 2026
* Release 4.0.0: bump version to 4.0.0 and update changelog - Update __version__ to 4.0.0 - Date the 4.0.0 changelog section (2026-09-27) - Add missing issue/PR references (#904, #919, #931, #932, #934, #938, #951, #963) - Fix Python 3.8 removal attribution (#932 instead of #930) Co-authored-by: JonathanHuot <[email protected]> * Update CHANGELOG.rst * Release 4.0.0: clarify changelog breaking changes and reformat entries Co-authored-by: JonathanHuot <[email protected]> --------- Co-authored-by: Asif Saif Uddin {"Auvi":"অভি"} <[email protected]>
This was referenced Sep 29, 2026
Closed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
JSONP was useful in the past for cross-origin requests but has been superseded by CORS browser protections. This change removes the outdated JSONP functionality.
Breaking Changes
enable_jsonpparameter fromRevocationEndpointcallbackparameter fromprepare_token_revocation_requestChanges
enable_jsonpparameter in constructorprepare_token_revocation_requestno longer acceptscallbackparameterMigration Guide
If you were using JSONP:
Rationale
Modern browsers have comprehensive CORS support, making JSONP unnecessary and potentially insecure. JSONP opens up security vulnerabilities that CORS specifically addresses.
Tests
All existing tests pass with the JSONP-specific tests removed.