fix: conditionally include offline_access in Flow 2 scope request
Flow 2 hardcoded offline_access in the scope string, but providers like AWS Cognito don't support this scope (they handle refresh tokens via client config). This caused invalid_scope errors on the Astrolabe semantic search enablement flow. Only include offline_access when enable_offline_access is explicitly set, matching the behavior of DCR scope registration. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 4.6
parent
c2b19a2983
commit
f8fb34d113
@@ -452,9 +452,11 @@ async def oauth_authorize_nextcloud(
|
|||||||
mcp_server_url = oauth_config["mcp_server_url"]
|
mcp_server_url = oauth_config["mcp_server_url"]
|
||||||
callback_uri = f"{mcp_server_url}/oauth/callback"
|
callback_uri = f"{mcp_server_url}/oauth/callback"
|
||||||
|
|
||||||
# Flow 2: Server only needs identity + offline access (no resource scopes)
|
# Flow 2: Server only needs identity + optional offline access (no resource scopes)
|
||||||
# Resource scopes are requested by client in Flow 1
|
# Resource scopes are requested by client in Flow 1
|
||||||
scopes = "openid profile email offline_access"
|
scopes = "openid profile email"
|
||||||
|
if get_settings().enable_offline_access:
|
||||||
|
scopes += " offline_access"
|
||||||
|
|
||||||
# Generate PKCE values (required by Nextcloud OIDC)
|
# Generate PKCE values (required by Nextcloud OIDC)
|
||||||
code_verifier = secrets.token_urlsafe(32)
|
code_verifier = secrets.token_urlsafe(32)
|
||||||
|
|||||||
Reference in New Issue
Block a user