-
Notifications
You must be signed in to change notification settings - Fork 1.5k
Connection with OAuth doesn't include scopes #454
Copy link
Copy link
Closed as not planned
Labels
authIssues and PRs related to authorizationIssues and PRs related to authorizationbugSomething isn't workingSomething isn't workingclosed-v1-deprecatedClosed: v1 is deprecated and accepting security fixes onlyClosed: v1 is deprecated and accepting security fixes onlyv1waiting on sdkWaiting for an SDK featureWaiting for an SDK feature
Description
Activity
Metadata
Metadata
Assignees
Labels
authIssues and PRs related to authorizationIssues and PRs related to authorizationbugSomething isn't workingSomething isn't workingclosed-v1-deprecatedClosed: v1 is deprecated and accepting security fixes onlyClosed: v1 is deprecated and accepting security fixes onlyv1waiting on sdkWaiting for an SDK featureWaiting for an SDK feature
Describe the bug
The OAuth debugger includes all the
scopes_supportedvalues in the Authorization URL step as a query param, but even if scope is marked asrequiredin the authorization server metadata, thescopequery param isn't included in the URL when clicking the "Connect" button.Expected behavior
The authorization URL for the two OAuth connection methods (debugger or simple "connect" button) should match exactly.
Related PR: #355