fix(oauth): reject user-scoped clients on single-workspace hosts - #1894
Open
The-AarushiSingh wants to merge 1 commit into
Open
fix(oauth): reject user-scoped clients on single-workspace hosts#1894The-AarushiSingh wants to merge 1 commit into
The-AarushiSingh wants to merge 1 commit into
Conversation
- Reject owner: 'user' when deps.subject === 'local' - Keep user-owned OAuth clients working for other subjects - Update mismatch error to avoid 'Workspace' terminology Closes UsefulSoftwareCo#1850
Contributor
Author
|
cloud 13of16 is |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #1850
On local/desktop the executor subject is
LOCAL_SUBJECT("local") and every connection is org-scoped.createClientstill acceptedowner: "user", so those clients could never be used. The later mismatch error also used cloud wording (“A Workspace connection must use a Workspace app.”).Change
createClient, rejectowner: "user"whendeps.subject === "local".test-subject/subject-a/subject-b, so existing user-client tests are unchanged.An org connection must use an org-owned OAuth client.No new config. No silent remap of
user→org.Test
"local"+owner: "user"returns the new error.