trails/openspec/changes/wahoo-import/specs/journal-auth/spec.md
Ullrich Schäfer b6711d23d6
Add Wahoo activity sync with provider-agnostic framework
Provider-agnostic sync framework + Wahoo as first implementation:

Framework (apps/journal/app/lib/sync/):
- SyncProvider interface for OAuth2, webhooks, import, conversion
- Provider registry for settings UI iteration
- Generic sync_connections + sync_imports tables
- Token storage with auto-refresh

Wahoo provider:
- OAuth2 with workouts_read, user_read, offline_data scopes
- Webhook-based auto-import (workout_summary events)
- Manual import page with pagination
- FIT→GPX conversion via fit-file-parser
- Webhook token verification

Routes:
- /api/sync/connect/:provider — OAuth redirect
- /api/sync/callback/:provider — OAuth callback
- /api/sync/disconnect/:provider — remove connection
- /api/sync/webhook/:provider — webhook receiver
- /sync/import/:provider — manual import page

Settings: Connected Services section with per-provider connect/disconnect

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-04 11:22:02 +01:00

422 B

MODIFIED Requirements

Requirement: Store external service tokens

The journal auth system SHALL store OAuth tokens for external services alongside user credentials.

Scenario: Wahoo token storage

  • WHEN a user connects their Wahoo account
  • THEN access token, refresh token, expiry time, and Wahoo user ID are stored in the wahoo_tokens table
  • AND tokens are associated with the journal user ID