From e20f1de58a70978580e64f80252aea89b3343d70 Mon Sep 17 00:00:00 2001 From: Ludovic Vielle Date: Wed, 17 Jun 2026 16:14:12 +0200 Subject: [PATCH] Backfill OAuth2 access token API scopes OAuth grant tokens issued before API scope enforcement only stored OIDC scopes. Set every existing iam_oauth2_access_tokens row to the full supported scope set so bearer tokens keep working under the OAuth2 scope gate. Signed-off-by: Ludovic Vielle --- pkg/coredata/migrations/20260618T120001Z.sql | 70 ++++++++++++++++++++ 1 file changed, 70 insertions(+) create mode 100644 pkg/coredata/migrations/20260618T120001Z.sql diff --git a/pkg/coredata/migrations/20260618T120001Z.sql b/pkg/coredata/migrations/20260618T120001Z.sql new file mode 100644 index 000000000..1c7f28e47 --- /dev/null +++ b/pkg/coredata/migrations/20260618T120001Z.sql @@ -0,0 +1,70 @@ +-- Copyright (c) 2026 Probo Inc . +-- +-- Permission to use, copy, modify, and/or distribute this software for any +-- purpose with or without fee is hereby granted, provided that the above +-- copyright notice and this permission notice appear in all copies. +-- +-- THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES WITH +-- REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY +-- AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY SPECIAL, DIRECT, +-- INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM +-- LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE OR +-- OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR +-- PERFORMANCE OF THIS SOFTWARE. + +-- OAuth grant tokens issued before API scope enforcement only carried OIDC +-- scopes (openid, profile, email, offline_access). Grant the full supported +-- scope set so existing bearer tokens keep working under the OAuth2 scope gate. +-- Refresh tokens copy scopes onto every newly minted access token, so both +-- token tables must be backfilled. +DO $$ +DECLARE + full_scopes TEXT[] := ARRAY[ + 'openid', + 'profile', + 'email', + 'offline_access', + 'v1:access-review', + 'v1:access-review:read', + 'v1:agent', + 'v1:agent:read', + 'v1:asset', + 'v1:asset:read', + 'v1:audit', + 'v1:audit:read', + 'v1:common-third-party', + 'v1:common-third-party:read', + 'v1:compliance-page', + 'v1:compliance-page:read', + 'v1:connector', + 'v1:connector:read', + 'v1:control', + 'v1:control:read', + 'v1:datum', + 'v1:datum:read', + 'v1:document', + 'v1:document:read', + 'v1:iam', + 'v1:iam:read', + 'v1:org', + 'v1:org:read', + 'v1:privacy', + 'v1:privacy:read', + 'v1:risk', + 'v1:risk:read', + 'v1:slack-connection', + 'v1:slack-connection:read', + 'v1:task', + 'v1:task:read', + 'v1:third-party', + 'v1:third-party:read', + 'v1:webhook', + 'v1:webhook:read' + ]::TEXT[]; +BEGIN + UPDATE iam_oauth2_access_tokens + SET scopes = full_scopes; + + UPDATE iam_oauth2_refresh_tokens + SET scopes = full_scopes; +END $$;