Repository navigation
feat: add oauth2 scope columns and single-use delete queries #28007
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from 1 commit
7efa327
50f3466
6f5e057
e3ca40d
5ca9beb
3375487
08f2c9a
852d983
bfc9fd0
a95174e
5df995e
02076e1
f8a930a
a494c86
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
Migration 000567 adds a nullable `scope text` to oauth2_provider_app_codes and oauth2_provider_app_tokens so the scope negotiated at /oauth2/authorize can travel from a code to the token it is exchanged for. No backfill, and every insert writes NULL for now, which reads as unrestricted access, so behavior is unchanged. DeleteOAuth2ProviderAppCodeByIDReturningID and DeleteAPIKeyByIDReturningID return sql.ErrNoRows when the row is already gone, letting the grant paths enforce single use without a read-then-write race. The existing blind deletes and their call sites are unchanged. Refs PLAT-478
- Loading branch information
There are no files selected for viewing
Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.
Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.
Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,3 @@ | ||
| ALTER TABLE oauth2_provider_app_codes DROP COLUMN scope; | ||
|
|
||
| ALTER TABLE oauth2_provider_app_tokens DROP COLUMN scope; |
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,16 @@ | ||
| -- The scope negotiated at /oauth2/authorize travels with the grant itself: | ||
| -- recorded on the code when it is issued, then carried onto the token it is | ||
| -- exchanged for so a refresh can narrow against what was actually granted | ||
| -- rather than against the app's current allowlist. | ||
| -- | ||
| -- Both columns are nullable with no backfill. A NULL means "no scope was | ||
| -- recorded for this grant", which the token endpoint reads as unrestricted | ||
| -- access, so codes and tokens issued before this migration keep working. | ||
|
|
||
| ALTER TABLE oauth2_provider_app_codes ADD COLUMN scope text; | ||
|
|
||
| ALTER TABLE oauth2_provider_app_tokens ADD COLUMN scope text; | ||
|
|
||
| COMMENT ON COLUMN oauth2_provider_app_codes.scope IS 'Space-separated scope negotiated at authorization time. NULL means no scope was recorded and the exchanged token is unrestricted.'; | ||
|
|
||
| COMMENT ON COLUMN oauth2_provider_app_tokens.scope IS 'Space-separated scope granted to this token. A refresh may narrow this but never widen it. NULL means no scope was recorded and the token is unrestricted.'; | ||
|
BobbyHo marked this conversation as resolved.
Outdated
|
||
Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.
Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.
Uh oh!
There was an error while loading. Please reload this page.