OAuth

Exchange a live platform session for an authorize continuation

Rung 1 of the /authorize identity ladder: reuse the platform session.

The login page's script posts the pending authorize state (the ls carry-through token) with the SPA's bearer token in the Authorization header — no cookies, no ambient credentials, so a cross-site form cannot drive it (same CSRF posture as the consent POST and the inline approval decision). The platform token is validated by the standard auth dependency (users only), and the active / must_change_password fences are re-checked with a LIVE user-row read — not the token's baked claims — matching rung 3's password_rotation_required posture, so an admin-forced reset fences the exchange immediately even while pre-reset SPA tokens are still in flight. The D7 client gate is re-checked, and on success the response carries a relative /authorize resume URL bearing a short-TTL, session-purpose continuation blob that pins THIS caller's user_id — the identity is fixed at exchange time, before the consent page renders it with its "Not you?" escape.

Every failure after authentication is the same generic 400: an invalid blob must not let the caller learn anything about the client or the flow.

post/oauth/session/continue

Request body

statestring required

Response

Successful Response

redirect_urlstring required

Changes

Changed in 1 of the 114 revisions of this API.1