Repository navigation
fix(oauth): request the scopes the extension and CLI actually need - #1138
Conversation
e5d637a to
f7c24db
Compare
54dde24 to
e40f20e
Compare
Servers that enforce OAuth scopes (from 2.38) refused the extension right after sign-in: `/users/me` needs `user:read`. Request what the extension and the CLI it runs need: the `coder:workspaces.operate` and `coder:workspaces.access` composites, `workspace:create`, `user:read` and `user:read_personal`. Request `inbox_notification:read` only when the server lists it in `scopes_supported`, since servers reject unknown scopes and 2.38 does not offer it yet. Store `coder:all` when the server returns no scope, as servers that ignore scopes grant everything, so later scope changes do not sign their users out. Sessions stored with the old list sign in again once. Revoke tokens on logout even when their scopes are outdated, and accept sessions granted `coder:all`.
e40f20e to
5b913e9
Compare
code-asher
left a comment
There was a problem hiding this comment.
Tested it out, looks good!
|
Ah one thing I realized, if the scopes change, we make them log in again, but I think we are not revoking the old token with the old scopes when this happens? Because the code treats it more like the token never existed at all rather than a logout/login. We probably should revoke the old token? Also |
Fixes VSC-24
Split out of #1128, which holds the live-server scope suite and is stacked on this PR.
Problem
Servers that enforce OAuth scopes (from 2.38) refuse the extension right after sign-in:
GET /users/meneedsuser:read. An audit against a live server (#1128) found more gaps with the same cause:user:read. Without it, remote SSH, ping, speedtest, support bundle,coder startandcoder updatebreak.user:read(owner lookup), and stop builds needworkspace:stop.organization_member:read, which only thecoder:workspaces.*composites grant.coder startdry-runs a build when a workspace must update first (workspace:create).inbox_notification:read(fix: let scoped tokens list and mark inbox notifications read coder#30176).Fix
The extension requests:
inbox_notification:readis requested only when the server lists it inscopes_supported(IF_SUPPORTED_OAUTH_SCOPES). Servers reject the whole request over an unknown scope, andrelease/2.38doesn't offer it yet. Stored sessions don't need it.scope, the extension storescoder:all. Only servers that ignore scopes do that, and they grant everything, so later scope changes don't sign their users out. OnlyhasRequiredScopesreads it; it is never sent to the server.getStoredTokensno longer checks scopes;getTokensWithRequiredScopesdoes, and every caller exceptrevokeTokensuses it.Everyone signed in with OAuth signs in again once, because their stored sessions lack the new scopes. The CHANGELOG says so.
Size
+113/−35 in 9 files:
src/oauth: +49/−27.Tests
Unit tests cover:
IF_SUPPORTED_OAUTH_SCOPESonly when the server supports themcoder:allcoder:allwhen the server returns no scope#1128 runs every request against a live server.
🤖 Generated with Claude Code