]> dgit.raspbian.org Git - dovecot.git/commitdiff
[PATCH 1/4] auth: db-oauth2: Reduce nesting in token_in_scope via early return
authorAki Tuomi <aki.tuomi@open-xchange.com>
Wed, 3 Jun 2026 12:56:13 +0000 (12:56 +0000)
committerNoah Meyerhans <noahm@debian.org>
Wed, 16 Sep 2026 19:06:35 +0000 (15:06 -0400)
Gbp-Pq: Name 0001-auth-db-oauth2-Reduce-nesting-in-token_in_scope-via-.patch

src/auth/db-oauth2.c

index 230c6cf7678a5fa356fe38932a41eb0b2d1b63cf..ed1bf013c35a268d5f14337be70de58db8ccd045 100644 (file)
@@ -553,32 +553,32 @@ static bool
 db_oauth2_token_in_scope(struct db_oauth2_request *req,
                         enum passdb_result *result_r, const char **error_r)
 {
-       bool found = TRUE;
-       if (!array_is_empty(&req->db->set->scope)) {
-               found = FALSE;
-               const char *value = auth_fields_find(req->fields, "scope");
-               bool has_scope = value != NULL;
-               if (!has_scope)
-                       value = auth_fields_find(req->fields, "aud");
-               e_debug(authdb_event(req->auth_request),
-                       "Token scope(s): %s",
-                       value);
-               if (value != NULL) {
-                       const char *wanted_scope;
-                       const char *const *entries = has_scope ?
-                               t_strsplit_spaces(value, " ") :
-                               t_strsplit_tabescaped(value);
-                       array_foreach_elem(&req->db->set->scope, wanted_scope) {
-                               if ((found = str_array_find(entries, wanted_scope)))
-                                       break;
-                       }
-               }
-               if (!found) {
-                       *error_r = t_strdup_printf("Token is not valid for scope '%s'",
-                                                  req->db->oauth2_set.scope);
-                       *result_r = PASSDB_RESULT_USER_DISABLED;
+       if (array_is_empty(&req->db->set->scope))
+               return TRUE;
+
+       bool found = FALSE;
+       const char *value = auth_fields_find(req->fields, "scope");
+       bool has_scope = value != NULL;
+       if (!has_scope)
+               value = auth_fields_find(req->fields, "aud");
+       e_debug(authdb_event(req->auth_request),
+               "Token scope(s): %s",
+               value);
+       if (value != NULL) {
+               const char *wanted_scope;
+               const char *const *entries = has_scope ?
+                       t_strsplit_spaces(value, " ") :
+                       t_strsplit_tabescaped(value);
+               array_foreach_elem(&req->db->set->scope, wanted_scope) {
+                       if ((found = str_array_find(entries, wanted_scope)))
+                               break;
                }
        }
+       if (!found) {
+               *error_r = t_strdup_printf("Token is not valid for scope '%s'",
+                       t_array_const_string_join(&req->db->set->scope, " "));
+               *result_r = PASSDB_RESULT_USER_DISABLED;
+       }
        return found;
 }