Fix missing cmid scope

Signed-off-by: Bryan Frimin <bryan@probo.com>
This commit is contained in:
Bryan Frimin
2026-06-19 18:49:33 +02:00
parent 8add4713c8
commit 9fd95a0bf9
19 changed files with 611 additions and 646 deletions

View File

@@ -334,14 +334,6 @@ func (f *cimdFetcher) storeCache(clientIDURL string, doc *ClientMetadataDocument
)
}
func (s *Service) ResolveClient(
ctx context.Context,
clientIDRaw string,
redirectURI string,
) (*coredata.OAuth2Client, error) {
return s.resolveClient(ctx, nil, clientIDRaw, redirectURI)
}
func (s *Service) resolveClient(
ctx context.Context,
tx pg.Tx,
@@ -415,7 +407,7 @@ func (s *Service) upsertCIMDClient(
ScopeEmail,
ScopeOfflineAccess,
},
s.apiScopes,
s.scopeSet.APIScopes(),
)
now := time.Now()

View File

@@ -33,6 +33,7 @@ import (
"go.probo.inc/probo/pkg/gid"
"go.probo.inc/probo/pkg/net"
"go.probo.inc/probo/pkg/page"
"go.probo.inc/probo/pkg/iam/scopeset"
"go.probo.inc/probo/pkg/uri"
)
@@ -62,7 +63,7 @@ type (
gc *GarbageCollector
cimd *cimdFetcher
cimdAllowedClientIDs []string
apiScopes []coredata.OAuth2Scope
scopeSet *scopeset.ScopeSet
accessTokenDuration time.Duration
refreshTokenDuration time.Duration
authorizationCodeDuration time.Duration
@@ -159,9 +160,9 @@ func WithDeviceCodeDuration(d time.Duration) Option {
}
}
func WithAPIScopes(scopes []coredata.OAuth2Scope) Option {
func WithScopeSet(scopeSet *scopeset.ScopeSet) Option {
return func(s *Service) {
s.apiScopes = scopes
s.scopeSet = scopeSet
}
}
@@ -1438,6 +1439,8 @@ func (s *Service) Authorize(
return err
}
fmt.Printf("X: %+v\n", client)
if !client.IsRedirectURIAllowed(req.RedirectURI) {
return ErrInvalidRedirectURI
}
@@ -1736,7 +1739,7 @@ func (s *Service) AuthenticateClient(
clientIDRaw string,
clientSecret string,
) (*coredata.OAuth2Client, error) {
client, err := s.ResolveClient(ctx, clientIDRaw, "")
client, err := s.resolveClient(ctx, nil, clientIDRaw, "")
if err != nil {
return nil, err
}