Files
quantconnect--lean/Brokerages/Authentication/LeanTokenCredentials.cs
T
Roman Yavnikov 541682fa4e
Python Virtual Environments / build (push) Has been cancelled
Benchmarks / build (push) Has been cancelled
Build & Test Lean / build (push) Has been cancelled
Regression Tests / build (push) Has been cancelled
Research Regression Tests / build (push) Has been cancelled
Syntax Tests / build (push) Has been cancelled
Report Generator Tests / build (push) Has been cancelled
API Tests / build (push) Has been cancelled
feat: add CreateOAuthTokenHandler factory to Brokerage base class (#9330)
* feat: add CreateOAuthTokenHandler factory to Brokerage base class

Introduce AuthenticationFailed event on TokenHandler raised when all
retry attempts are exhausted. Add CreateOAuthTokenHandler<TRequest,TResponse>
protected factory method on Brokerage that wires the event to OnMessage
(BrokerageMessageType.Error), triggering graceful Lean shutdown on
OAuth token refresh failure without requiring per-brokerage error logic.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* refactor: token retry logic: move to OAuthTokenHandler

* refactor: replace generic OAuthTokenHandler with non-generic, require explicit token lifetime

- Remove generic type parameters <TRequest, TResponse> from OAuthTokenHandler and
  CreateOAuthTokenHandler; use LeanAccessTokenMetaDataRequest and
  AccessTokenMetaDataResponse directly
- Delete abstract AccessTokenMetaDataRequest; logic moved to LeanAccessTokenMetaDataRequest
- Make tokenLifetime a required constructor parameter — each brokerage must explicitly
  declare its OAuth token lifetime to prevent silent 1-hour fallback bugs
- Move expiry tracking into the handler via _tokenExpiresAt (written under lock before the
  volatile write of _tokenCredentials, ensuring correct visibility on the fast path)
- Simplify AccessTokenMetaDataResponse to a concrete class with { get; set; } properties

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* test: add unit tests for OAuthTokenHandler and AccessTokenMetaDataResponse

- Make ApiConnection.TryRequest<T>(HttpRequestMessage) virtual to allow
  test subclasses to intercept without real HTTP calls
- Add AccessTokenMetaDataResponseTests: two parameterized cases verify that
  TokenType defaults to Bearer when absent from JSON (CharlesSchwab pattern)
  and deserializes correctly when present (Tastytrade pattern)
- Add OAuthTokenHandlerTests with FakeApiConnection stub:
  CharlesSchwab-style response (no tokenType, 30-min lifetime) and
  Tastytrade-style response (explicit tokenType + expiresIn/tokenId, 15-min lifetime)

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* refactor: backward-compatible OAuth auth with new LeanOAuthTokenHandler hierarchy

- Restore master API: OAuthTokenHandler<TReq,TRes>, AccessTokenMetaDataRequest,
  AccessTokenMetaDataResponse, and TokenHandler stay source-compatible for old consumers
- Extend TokenHandler with AuthenticationFailed event; simplify Send() (auth header only)
- Add LeanOAuthTokenHandler: non-generic, thread-safe double-checked locking, explicit
  tokenLifetime, retry logic in GetAccessToken, fires AuthenticationFailed on exhaustion
- Add OAuthTokenRequest / OAuthTokenResponse: concrete Lean platform request/response
- Brokerage.CreateOAuthTokenHandler wires AuthenticationFailed to graceful shutdown
- Update tests: OAuthTokenResponseTests, LeanOAuthTokenHandlerTests, TokenHandlerTests

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* Some tweaks

---------

Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
Co-authored-by: Martin Molinero <martin.molinero1@gmail.com>
2026-03-14 13:10:52 -03:00

55 lines
1.9 KiB
C#

/*
* QUANTCONNECT.COM - Democratizing Finance, Empowering Individuals.
* Lean Algorithmic Trading Engine v2.0. Copyright 2014 QuantConnect Corporation.
*
* Licensed under the Apache License, Version 2.0 (the "License");
* you may not use this file except in compliance with the License.
* You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0
*
* Unless required by applicable law or agreed to in writing, software
* distributed under the License is distributed on an "AS IS" BASIS,
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
* See the License for the specific language governing permissions and
* limitations under the License.
*/
using QuantConnect.Api;
namespace QuantConnect.Brokerages.Authentication
{
/// <summary>
/// Represents credentials required for token-based authentication,
/// including the access token and its type (e.g., Bearer).
/// </summary>
public class LeanTokenCredentials : RestResponse
{
/// <summary>
/// Gets the type of the token (e.g., Bearer).
/// </summary>
public TokenType TokenType { get; set; }
/// <summary>
/// Gets the token string used for authentication.
/// </summary>
public string AccessToken { get; set; }
/// <summary>
/// Initializes a new instance of the <see cref="LeanTokenCredentials"/> class.
/// </summary>
/// <param name="tokenType">The type of the token.</param>
/// <param name="accessToken">The token string.</param>
public LeanTokenCredentials(TokenType tokenType, string accessToken)
{
TokenType = tokenType;
AccessToken = accessToken;
}
/// <summary>
/// Initializes a new instance of the <see cref="LeanTokenCredentials"/> class.
/// </summary>
public LeanTokenCredentials()
{
}
}
}