mirror of
https://github.com/netbirdio/dex.git
synced 2026-05-22 18:43:53 -07:00
Merge pull request #4203 from rackerlabs/fix-device-code
fix: device code should not require scope
This commit is contained in:
@@ -85,6 +85,12 @@ func (s *Server) handleDeviceCode(w http.ResponseWriter, r *http.Request) {
|
||||
return
|
||||
}
|
||||
|
||||
if len(scopes) == 0 {
|
||||
// per RFC8628 section 3.1, https://datatracker.ietf.org/doc/html/rfc8628#section-3.1
|
||||
// scope is optional but dex requires that it is always at least 'openid' so default it
|
||||
scopes = []string{"openid"}
|
||||
}
|
||||
|
||||
s.logger.InfoContext(r.Context(), "received device request", "client_id", clientID, "scoped", scopes)
|
||||
|
||||
// Make device code
|
||||
|
||||
@@ -90,6 +90,14 @@ func TestHandleDeviceCode(t *testing.T) {
|
||||
expectedResponseCode: http.StatusBadRequest,
|
||||
expectedContentType: "application/json",
|
||||
},
|
||||
{
|
||||
testName: "New Code without scope",
|
||||
clientID: "test",
|
||||
requestType: "POST",
|
||||
scopes: []string{},
|
||||
expectedResponseCode: http.StatusOK,
|
||||
expectedContentType: "application/json",
|
||||
},
|
||||
}
|
||||
for _, tc := range tests {
|
||||
t.Run(tc.testName, func(t *testing.T) {
|
||||
|
||||
Reference in New Issue
Block a user