fix: conditionally include offline_access based on IdP discovery

AWS Cognito provides refresh tokens automatically with the authorization
code flow but does not list offline_access as a supported scope. Check
the IdP's scopes_supported discovery field before including it in
requests, and always accept refresh tokens from responses regardless.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
This commit is contained in:
Chris Coutinho
2026-04-07 23:48:49 +02:00
co-authored by Claude Opus 4.6
parent 776e2ce693
commit 7730f926cb
5 changed files with 331 additions and 10 deletions
+6 -1
View File
@@ -468,11 +468,14 @@ async def check_logged_in(ctx: Context, user_id: Optional[str] = None) -> str:
)
# Define scopes for Nextcloud access
# Note: offline_access is only included when enabled in settings.
# The actual scope sent to the IdP is determined by
# oauth_authorize_nextcloud() based on IdP discovery, so this list
# is informational (generate_oauth_url_for_flow2 marks it as unused).
scopes = [
"openid",
"profile",
"email",
"offline_access", # Critical for background operations
"notes.read",
"notes.write",
"calendar.read",
@@ -482,6 +485,8 @@ async def check_logged_in(ctx: Context, user_id: Optional[str] = None) -> str:
"files.read",
"files.write",
]
if get_settings().enable_offline_access:
scopes.insert(3, "offline_access")
# Generate authorization URL
auth_url = generate_oauth_url_for_flow2(