From: Aki Tuomi Date: Wed, 3 Jun 2026 12:56:20 +0000 (+0000) Subject: [PATCH 2/4] auth: db-oauth2: Fix scope check to require all configured scopes X-Git-Tag: archive/raspbian/1%2.4.1+dfsg1-6+rpi1+deb13u7^2~73 X-Git-Url: https://dgit.raspbian.org/?a=commitdiff_plain;h=e8721851fd79a39e93e0528f245448a76e7d255a;p=dovecot.git [PATCH 2/4] auth: db-oauth2: Fix scope check to require all configured scopes Switch token-in-scope check to AND semantics: all configured scopes must be present in the token. Behaviour now matches the JWT path. Gbp-Pq: Name 0002-auth-db-oauth2-Fix-scope-check-to-require-all-config.patch --- diff --git a/src/auth/db-oauth2.c b/src/auth/db-oauth2.c index ed1bf01..159344f 100644 --- a/src/auth/db-oauth2.c +++ b/src/auth/db-oauth2.c @@ -556,22 +556,25 @@ db_oauth2_token_in_scope(struct db_oauth2_request *req, if (array_is_empty(&req->db->set->scope)) return TRUE; - bool found = FALSE; const char *value = auth_fields_find(req->fields, "scope"); bool has_scope = value != NULL; if (!has_scope) value = auth_fields_find(req->fields, "aud"); e_debug(authdb_event(req->auth_request), - "Token scope(s): %s", - value); - if (value != NULL) { - const char *wanted_scope; + "Token scope(s): %s", value); + + bool found = FALSE; + if (value != NULL && *value != '\0') { const char *const *entries = has_scope ? t_strsplit_spaces(value, " ") : t_strsplit_tabescaped(value); - array_foreach_elem(&req->db->set->scope, wanted_scope) { - if ((found = str_array_find(entries, wanted_scope))) + const char *wanted; + found = TRUE; + array_foreach_elem(&req->db->set->scope, wanted) { + if (!str_array_find(entries, wanted)) { + found = FALSE; break; + } } } if (!found) {