From: Aki Tuomi Date: Wed, 3 Jun 2026 12:56:13 +0000 (+0000) Subject: [PATCH 1/4] auth: db-oauth2: Reduce nesting in token_in_scope via early return X-Git-Tag: archive/raspbian/1%2.4.1+dfsg1-6+rpi1+deb13u7^2~74 X-Git-Url: https://dgit.raspbian.org/?a=commitdiff_plain;h=754db810f24e10bc3dc0510cee2dd328c75529e9;p=dovecot.git [PATCH 1/4] auth: db-oauth2: Reduce nesting in token_in_scope via early return Gbp-Pq: Name 0001-auth-db-oauth2-Reduce-nesting-in-token_in_scope-via-.patch --- diff --git a/src/auth/db-oauth2.c b/src/auth/db-oauth2.c index 230c6cf..ed1bf01 100644 --- a/src/auth/db-oauth2.c +++ b/src/auth/db-oauth2.c @@ -553,32 +553,32 @@ static bool db_oauth2_token_in_scope(struct db_oauth2_request *req, enum passdb_result *result_r, const char **error_r) { - bool found = TRUE; - if (!array_is_empty(&req->db->set->scope)) { - found = FALSE; - const char *value = auth_fields_find(req->fields, "scope"); - bool has_scope = value != NULL; - if (!has_scope) - value = auth_fields_find(req->fields, "aud"); - e_debug(authdb_event(req->auth_request), - "Token scope(s): %s", - value); - if (value != NULL) { - const char *wanted_scope; - const char *const *entries = has_scope ? - t_strsplit_spaces(value, " ") : - t_strsplit_tabescaped(value); - array_foreach_elem(&req->db->set->scope, wanted_scope) { - if ((found = str_array_find(entries, wanted_scope))) - break; - } - } - if (!found) { - *error_r = t_strdup_printf("Token is not valid for scope '%s'", - req->db->oauth2_set.scope); - *result_r = PASSDB_RESULT_USER_DISABLED; + if (array_is_empty(&req->db->set->scope)) + return TRUE; + + bool found = FALSE; + const char *value = auth_fields_find(req->fields, "scope"); + bool has_scope = value != NULL; + if (!has_scope) + value = auth_fields_find(req->fields, "aud"); + e_debug(authdb_event(req->auth_request), + "Token scope(s): %s", + value); + if (value != NULL) { + const char *wanted_scope; + const char *const *entries = has_scope ? + t_strsplit_spaces(value, " ") : + t_strsplit_tabescaped(value); + array_foreach_elem(&req->db->set->scope, wanted_scope) { + if ((found = str_array_find(entries, wanted_scope))) + break; } } + if (!found) { + *error_r = t_strdup_printf("Token is not valid for scope '%s'", + t_array_const_string_join(&req->db->set->scope, " ")); + *result_r = PASSDB_RESULT_USER_DISABLED; + } return found; }