mirror of
https://github.com/go-gitea/gitea.git
synced 2026-10-02 15:10:43 +02:00
fix(oauth2): allow users to approve scope changes (#38942)
Lets users approve an OAuth2 scope change on an existing grant instead of failing with `a grant exists with different scope`. - Approving a different scope updates the existing grant. Issued tokens follow immediately, since their scope is read from the grant. - Confidential and trusted apps show the consent page when the scope set changes, instead of silently reusing the old grant. - An omitted `scope` reuses the existing grant's scope, like GitHub. - The consent page lists newly added scopes. Fixes: https://github.com/go-gitea/gitea/issues/38940 Co-authored-by: bircni <bircni@icloud.com> Co-authored-by: Giteabot <teabot@gitea.io> Co-authored-by: silverwind <me@silverwind.io>
This commit is contained in:
5 files changed
+53
-7
No files matched your search
@@ -564,6 +564,12 @@ func (grant *OAuth2Grant) SetNonce(ctx context.Context, nonce string) error {
|
||||
return nil
|
||||
}
|
||||
|
||||
func UpdateGrantScope(ctx context.Context, grant *OAuth2Grant, newScope string) error {
|
||||
grant.Scope = newScope
|
||||
_, err := db.GetEngine(ctx).ID(grant.ID).Cols("scope").Update(grant)
|
||||
return err
|
||||
}
|
||||
|
||||
// GetOAuth2GrantByID returns the grant with the given ID
|
||||
func GetOAuth2GrantByID(ctx context.Context, id int64) (grant *OAuth2Grant, err error) {
|
||||
grant = new(OAuth2Grant)
|
||||
|
||||
Reference in new issue
Block a user