]> dgit.raspbian.org Git - dovecot.git/commitdiff
[PATCH 2/4] auth: db-oauth2: Fix scope check to require all configured scopes
authorAki Tuomi <aki.tuomi@open-xchange.com>
Wed, 3 Jun 2026 12:56:20 +0000 (12:56 +0000)
committerNoah Meyerhans <noahm@debian.org>
Wed, 16 Sep 2026 19:06:35 +0000 (15:06 -0400)
Switch token-in-scope check to AND semantics: all configured scopes
must be present in the token. Behaviour now matches the JWT path.

Gbp-Pq: Name 0002-auth-db-oauth2-Fix-scope-check-to-require-all-config.patch

src/auth/db-oauth2.c

index ed1bf013c35a268d5f14337be70de58db8ccd045..159344f9ad6b0518863c077d1f7d80494ec1825b 100644 (file)
@@ -556,22 +556,25 @@ db_oauth2_token_in_scope(struct db_oauth2_request *req,
        if (array_is_empty(&req->db->set->scope))
                return TRUE;
 
-       bool found = FALSE;
        const char *value = auth_fields_find(req->fields, "scope");
        bool has_scope = value != NULL;
        if (!has_scope)
                value = auth_fields_find(req->fields, "aud");
        e_debug(authdb_event(req->auth_request),
-               "Token scope(s): %s",
-               value);
-       if (value != NULL) {
-               const char *wanted_scope;
+               "Token scope(s): %s", value);
+
+       bool found = FALSE;
+       if (value != NULL && *value != '\0') {
                const char *const *entries = has_scope ?
                        t_strsplit_spaces(value, " ") :
                        t_strsplit_tabescaped(value);
-               array_foreach_elem(&req->db->set->scope, wanted_scope) {
-                       if ((found = str_array_find(entries, wanted_scope)))
+               const char *wanted;
+               found = TRUE;
+               array_foreach_elem(&req->db->set->scope, wanted) {
+                       if (!str_array_find(entries, wanted)) {
+                               found = FALSE;
                                break;
+                       }
                }
        }
        if (!found) {