"""Schwab OAuth callback. Schwab requires an HTTPS callback URL. The usual answer is ``https://127.0.0.1:8182`` with a self-signed certificate, which means clicking through a browser warning on every re-authentication — and the refresh token expires weekly. There are also reports of Schwab refusing to register apps whose callback is a loopback address. This app already terminates real HTTPS, so it can receive the redirect itself. Deliberately unauthenticated: Schwab redirects a browser here and cannot attach the chart token. Nothing is stored — the page only echoes the query string of the request that produced it, which the caller already has in their address bar. Storing the code would mean a later, unauthenticated visitor could read it. The path is deliberately unrevealing. That is not a security control — the endpoint's safety is that it is inert — it simply avoids advertising which brokerage this host talks to. Treat it as fixed: changing a registered callback URL means editing the Schwab app, which can send it back through approval. """ from fastapi import APIRouter, Request from fastapi.responses import HTMLResponse router = APIRouter(prefix="/api") PAGE = """ Callback

{heading}

{body} """ RECEIVED = """

Paste this entire URL into the waiting login prompt:

Single use, and it expires within minutes. Do not share it.

Nothing was stored on the server. This page shows only the URL you just arrived with.

""" IDLE = """

OAuth callback endpoint. Register this exact URL with the provider:

{url}

Arriving here directly is expected and harmless — the useful version of this page is the one you are redirected to.

""" @router.get("/qt", response_class=HTMLResponse) def callback(request: Request) -> HTMLResponse: if request.query_params.get("code"): page = PAGE.format( heading="Authorisation received", body=RECEIVED.format(url=str(request.url)), ) else: page = PAGE.format( heading="Callback endpoint", body=IDLE.format(url=str(request.url).split("?")[0]), ) # Never cached: it carries a single-use authorisation code. return HTMLResponse(page, headers={"Cache-Control": "no-store"})