Register API scopes on prb CLI OAuth client

Device logins only requested OIDC scopes while the authorizer now
gates API calls on v1:* scopes. Register the full scope set on the
well-known prb client, request it at login via CLIClientScopes, and
cover the device flow in e2e.

Collapse API scopes under an accordion on the consent screen and
document scope sync for future namespace additions.

Signed-off-by: Ludovic Vielle <ludovic@probo.com>
This commit is contained in:
Ludovic Vielle
2026-06-18 14:25:06 +02:00
parent 26c5002932
commit fd2e0903ee
7 changed files with 259 additions and 1 deletions

View File

@@ -0,0 +1,61 @@
-- Copyright (c) 2026 Probo Inc <hello@probo.com>.
--
-- Permission to use, copy, modify, and/or distribute this software for any
-- purpose with or without fee is hereby granted, provided that the above
-- copyright notice and this permission notice appear in all copies.
--
-- THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES WITH
-- REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
-- AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY SPECIAL, DIRECT,
-- INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
-- LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE OR
-- OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
-- PERFORMANCE OF THIS SOFTWARE.
-- Register API scopes on the Probo CLI OAuth2 client so the device
-- authorization flow can request v1:* scopes under enforcement.
UPDATE iam_oauth2_clients
SET scopes = '{
openid,
profile,
email,
offline_access,
v1:access-review,
v1:access-review:read,
v1:agent,
v1:agent:read,
v1:asset,
v1:asset:read,
v1:audit,
v1:audit:read,
v1:common-third-party,
v1:common-third-party:read,
v1:compliance-page,
v1:compliance-page:read,
v1:connector,
v1:connector:read,
v1:control,
v1:control:read,
v1:datum,
v1:datum:read,
v1:document,
v1:document:read,
v1:iam,
v1:iam:read,
v1:org,
v1:org:read,
v1:privacy,
v1:privacy:read,
v1:risk,
v1:risk:read,
v1:slack-connection,
v1:slack-connection:read,
v1:task,
v1:task:read,
v1:third-party,
v1:third-party:read,
v1:webhook,
v1:webhook:read
}'::TEXT[],
updated_at = NOW()
WHERE id = 'AAAAAAAAAAAASwAAAAAAAAAAcHJiY2xp';

View File

@@ -0,0 +1,56 @@
-- Copyright (c) 2026 Probo Inc <hello@probo.com>.
--
-- Permission to use, copy, modify, and/or distribute this software for any
-- purpose with or without fee is hereby granted, provided that the above
-- copyright notice and this permission notice appear in all copies.
--
-- THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES WITH
-- REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
-- AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY SPECIAL, DIRECT,
-- INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
-- LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE OR
-- OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
-- PERFORMANCE OF THIS SOFTWARE.
-- Well-known OAuth2 client for Auditor Mode (prbaud).
-- Read scopes plus v1:control for measure mutations. Keep in sync with
-- Constants.OAuth2.scopes in the Auditor Mode macOS app.
INSERT INTO iam_oauth2_clients (
id,
tenant_id,
organization_id,
client_name,
visibility,
redirect_uris,
scopes,
grant_types,
response_types,
token_endpoint_auth_method,
created_at,
updated_at
) VALUES (
'AAAAAAAAAAAASwAAAAAAAAAAcHJiYXVk',
NULL,
NULL,
'Auditor Mode',
'public',
'{}',
'{
openid,
profile,
email,
offline_access,
v1:control:read,
v1:org:read,
v1:control
}'::TEXT[],
'{urn:ietf:params:oauth:grant-type:device_code,refresh_token}',
'{code}',
'none',
NOW(),
NOW()
)
ON CONFLICT (id) DO UPDATE
SET
scopes = EXCLUDED.scopes,
updated_at = NOW();