Backfill OAuth2 access token API scopes
OAuth grant tokens issued before API scope enforcement only stored OIDC scopes. Set every existing iam_oauth2_access_tokens row to the full supported scope set so bearer tokens keep working under the OAuth2 scope gate. Signed-off-by: Ludovic Vielle <ludovic@probo.com>
This commit is contained in:
70
pkg/coredata/migrations/20260618T120001Z.sql
Normal file
70
pkg/coredata/migrations/20260618T120001Z.sql
Normal file
@@ -0,0 +1,70 @@
|
||||
-- Copyright (c) 2026 Probo Inc <hello@probo.com>.
|
||||
--
|
||||
-- Permission to use, copy, modify, and/or distribute this software for any
|
||||
-- purpose with or without fee is hereby granted, provided that the above
|
||||
-- copyright notice and this permission notice appear in all copies.
|
||||
--
|
||||
-- THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES WITH
|
||||
-- REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
|
||||
-- AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY SPECIAL, DIRECT,
|
||||
-- INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
|
||||
-- LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE OR
|
||||
-- OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
-- PERFORMANCE OF THIS SOFTWARE.
|
||||
|
||||
-- OAuth grant tokens issued before API scope enforcement only carried OIDC
|
||||
-- scopes (openid, profile, email, offline_access). Grant the full supported
|
||||
-- scope set so existing bearer tokens keep working under the OAuth2 scope gate.
|
||||
-- Refresh tokens copy scopes onto every newly minted access token, so both
|
||||
-- token tables must be backfilled.
|
||||
DO $$
|
||||
DECLARE
|
||||
full_scopes TEXT[] := ARRAY[
|
||||
'openid',
|
||||
'profile',
|
||||
'email',
|
||||
'offline_access',
|
||||
'v1:access-review',
|
||||
'v1:access-review:read',
|
||||
'v1:agent',
|
||||
'v1:agent:read',
|
||||
'v1:asset',
|
||||
'v1:asset:read',
|
||||
'v1:audit',
|
||||
'v1:audit:read',
|
||||
'v1:common-third-party',
|
||||
'v1:common-third-party:read',
|
||||
'v1:compliance-page',
|
||||
'v1:compliance-page:read',
|
||||
'v1:connector',
|
||||
'v1:connector:read',
|
||||
'v1:control',
|
||||
'v1:control:read',
|
||||
'v1:datum',
|
||||
'v1:datum:read',
|
||||
'v1:document',
|
||||
'v1:document:read',
|
||||
'v1:iam',
|
||||
'v1:iam:read',
|
||||
'v1:org',
|
||||
'v1:org:read',
|
||||
'v1:privacy',
|
||||
'v1:privacy:read',
|
||||
'v1:risk',
|
||||
'v1:risk:read',
|
||||
'v1:slack-connection',
|
||||
'v1:slack-connection:read',
|
||||
'v1:task',
|
||||
'v1:task:read',
|
||||
'v1:third-party',
|
||||
'v1:third-party:read',
|
||||
'v1:webhook',
|
||||
'v1:webhook:read'
|
||||
]::TEXT[];
|
||||
BEGIN
|
||||
UPDATE iam_oauth2_access_tokens
|
||||
SET scopes = full_scopes;
|
||||
|
||||
UPDATE iam_oauth2_refresh_tokens
|
||||
SET scopes = full_scopes;
|
||||
END $$;
|
||||
Reference in New Issue
Block a user