Clarify the Client Credentials user field

Closes #3590930

Clarifies that the Client Credentials User field provides the runtime Drupal identity, including ownership and user-specific access behavior. The help text states that configured scopes grant token permissions and identifies the user 1 and administrator-role bypasses. It recommends a dedicated service account.

Adds a focused functional assertion for the revised description. It also makes the existing Client Credentials kernel setup use a non-superuser account so its scoped-resource assertion exercises normal scope-limited behavior.

Validation:

  • composer validate --no-check-publish
  • php -l simple_oauth.module
  • php -l tests/src/Functional/ConsumerFormGrantTypesValidationTest.php
  • php -l tests/src/Kernel/ClientCredentialsTest.php
  • git diff --check

PHPUnit, PHPCS, and PHPStan were not run locally because this isolated checkout has no installed dependencies. Project CI must provide runtime and standards confirmation.

Final branch pipeline 915591 passes Composer, composer-lint, cspell, and PHPCS. Its five PHPStan findings and Oauth2ScopePluginManagerLegacyTest::testDiscoveryDeprecated PHPUnit failure are the same failures present in target-branch pipeline 913049; GitLab marks all six as repeated failures on 6.1.x. The branch-specific translatable-string warning from pipeline 915585 was fixed in 287cb1cb, and 49e1ae29 corrected the administrator-role guidance after tracing the access-policy data flow.

This does not change token authorization or scope behavior.

AI was used to assist with this contribution.

Edited by Alex Urevick-Ackelsberg

Merge request reports

Loading
Loading