HomePhorge

Begin cleaning up OAuth scope handling

Description

Begin cleaning up OAuth scope handling

Summary:
Ref T7303. OAuth scope handling never got fully modernized and is a bit of a mess.

Also introduce implicit "ALWAYS" and "NEVER" scopes.

Always give tokens access to meta-methods like conduit.getcapabilities and conduit.query. These do not expose user information.

Test Plan:

  • Used a token to call user.whoami.
  • Used a token to call conduit.query.
  • Used a token to try to call user.query, got rebuffed.

Reviewers: chad

Reviewed By: chad

Maniphest Tasks: T7303

Differential Revision: https://secure.phabricator.com/D15593

Details

Provenance
epriestleyAuthored on Apr 3 2016, 8:25 AM
themackabuPushed on Mar 25 2025, 8:07 PM
Parents
rP694a8543d809: Modernize some OAuth Server code
Branches
Loading...
Tags
Loading...

Event Timeline