Skip to content

Remove JSONP support from token revocation - #951

Merged
JonathanHuot merged 3 commits into
masterfrom
feature/remove-jsonp
Jul 11, 2026
Merged

JonathanHuot merged 3 commits into
masterfrom
feature/remove-jsonp

Conversation

@JonathanHuot

Copy link
Copy Markdown
Member

JSONP was useful in the past for cross-origin requests but has been superseded by CORS browser protections. This change removes the outdated JSONP functionality.

Breaking Changes

  • Remove enable_jsonp parameter from RevocationEndpoint
  • Remove callback parameter from prepare_token_revocation_request
  • Remove JSONP documentation and examples
  • Remove JSONP tests

Changes

  • RevocationEndpoint: No longer accepts enable_jsonp parameter in constructor
  • Token revocation responses: Returns empty string on success instead of JSONP-wrapped responses
  • Client API: prepare_token_revocation_request no longer accepts callback parameter
  • Documentation: Removed JSONP examples and references

Migration Guide

If you were using JSONP:

# Before
endpoint = RevocationEndpoint(validator, enable_jsonp=True)

# After
endpoint = RevocationEndpoint(validator)
# Use CORS headers instead of JSONP for cross-origin requests

Rationale

Modern browsers have comprehensive CORS support, making JSONP unnecessary and potentially insecure. JSONP opens up security vulnerabilities that CORS specifically addresses.

Tests

All existing tests pass with the JSONP-specific tests removed.

JSONP was useful in the past for cross-origin requests but has been
superseded by CORS browser protections. This change removes the outdated
JSONP functionality.

Breaking changes:
- Remove enable_jsonp parameter from RevocationEndpoint
- Remove callback parameter from prepare_token_revocation_request
- Remove JSONP documentation and examples
- Remove JSONP tests

The token revocation endpoint now returns empty response bodies on
success instead of JSONP-wrapped responses.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR removes JSONP support from the OAuth 2.0 token revocation endpoint and client-side request preparation, aligning revocation flows with modern CORS-based cross-origin patterns and reducing exposure to JSONP-related risks.

Changes:

  • Removed enable_jsonp from RevocationEndpoint and stopped emitting JSONP-wrapped responses.
  • Removed explicit callback support from prepare_token_revocation_request (client API and parameter helper) and deleted JSONP-specific tests.
  • Added a WIP changelog entry documenting the breaking change.

Reviewed changes

Copilot reviewed 6 out of 6 changed files in this pull request and generated 2 comments.

Show a summary per file
File Description
tests/oauth2/rfc6749/endpoints/test_revocation_endpoint.py Removes the JSONP callback revocation response test.
tests/oauth2/rfc6749/clients/test_base.py Removes JSONP-style revocation request preparation test coverage.
oauthlib/oauth2/rfc6749/parameters.py Drops explicit callback param and always encodes params into the request body.
oauthlib/oauth2/rfc6749/endpoints/revocation.py Removes JSONP response wrapping and simplifies success response body to empty string.
oauthlib/oauth2/rfc6749/clients/base.py Removes JSONP documentation and the explicit callback arg from the client API.
CHANGELOG.rst Documents the breaking removal of JSONP support under WIP.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread oauthlib/oauth2/rfc6749/parameters.py
Comment thread oauthlib/oauth2/rfc6749/clients/base.py
auvipy and others added 2 commits May 23, 2026 12:02
Co-authored-by: Copilot Autofix powered by AI <[email protected]>
Prevent callback from being accepted via kwargs in prepare_token_revocation_request, and add a regression test to ensure callback now raises TypeError.

Co-authored-by: Copilot <[email protected]>
@JonathanHuot
JonathanHuot merged commit c21b611 into master Jul 11, 2026
30 checks passed
@JonathanHuot JonathanHuot added this to the 3.4.0 milestone Jul 11, 2026
@JonathanHuot JonathanHuot added Breaking Breaking change, to go in the next major release. OAuth2-Provider This impact the provider part of OAuth2 Cleanup and removed Cleanup labels Jul 11, 2026
@auvipy
auvipy deleted the feature/remove-jsonp branch July 11, 2026 12:34
@JonathanHuot JonathanHuot modified the milestones: 3.4.0, 4.0.0 Sep 27, 2026
auvipy added a commit that referenced this pull request Sep 28, 2026
* Release 4.0.0: bump version to 4.0.0 and update changelog

- Update __version__ to 4.0.0
- Date the 4.0.0 changelog section (2026-09-27)
- Add missing issue/PR references (#904, #919, #931, #932, #934, #938, #951, #963)
- Fix Python 3.8 removal attribution (#932 instead of #930)

Co-authored-by: JonathanHuot <[email protected]>

* Update CHANGELOG.rst

* Release 4.0.0: clarify changelog breaking changes and reformat entries

Co-authored-by: JonathanHuot <[email protected]>

---------


Co-authored-by: Asif Saif Uddin {"Auvi":"অভি"} <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Breaking Breaking change, to go in the next major release. OAuth2-Provider This impact the provider part of OAuth2

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants