oauth

Handles `POST /device_verification/approve`.

Changed on

Session-authed. Persists the user's consent via the same OAuthUserClientScopes::insert the web consent flow uses (consent is always recorded — never short-circuited on a pre-existing grant), then marks the device code approved and bound to the signed-in user.

post/api/v0/main-frontend/oauth/device_verification/approve

Request

  • The document declares no server URL.
  • Auth: none declared

Request body

user_codestring required

Response

Device authorization approved

statusstring required

"approved" or "denied".

Changes