Repository navigation
internal/authutil: treat an empty scope in a token response as absent - #1308
Merged
guglielmo-san merged 2 commits intoSep 30, 2026
Merged
guglielmo-san merged 2 commits into
guglielmo-san merged 2 commits into
Conversation
Contributor
Author
|
@guglielmo-san could you take a look when you have a moment? The workflows are waiting for maintainer approval (first-time contributor). I rebuilt the branch on today's |
ScopesFromToken returns nil when a token response has no scope, and both callers (AuthorizationCodeHandler and ClientCredentialsHandler) take nil to mean the requested scopes were granted, per RFC 6749 section 5.1. But a response with "scope": "" (or only whitespace) gave strings.Fields's empty, non-nil slice, so the handler recorded that no scope was granted. The next step-up authorization then unions that empty set with the challenged scopes and asks only for those, dropping the permissions granted in earlier rounds, which is what the SEP-2350 accumulation is meant to prevent. An empty scope names no scope-token (RFC 6749 section 3.3), so it carries no more information than an absent one. Return nil for it. TestScopesFromToken covers absent, single, multiple, form-encoded, non-string, empty and whitespace-only scopes; the last two fail without the change. It also brings the package to 100% statement coverage. Fixes modelcontextprotocol#1318 Signed-off-by: Akshita <110122283+akshita317@users.noreply.github.com>
akshita317
force-pushed
the
authutil/empty-token-scope
branch
from
September 29, 2026 14:04
19bf7fb to
46fa64a
Compare
guglielmo-san
approved these changes
Sep 30, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
ScopesFromToken returns nil when a token response has no scope, and
both callers (AuthorizationCodeHandler and ClientCredentialsHandler)
take nil to mean the requested scopes were granted, per RFC 6749
section 5.1. But a response with "scope": "" (or only whitespace) gave
strings.Fields's empty, non-nil slice, so the handler recorded that no
scope was granted. The next step-up authorization then unions that
empty set with the challenged scopes and asks only for those, dropping
the permissions granted in earlier rounds, which is what the SEP-2350
accumulation is meant to prevent.
An empty scope names no scope-token (RFC 6749 section 3.3), so it
carries no more information than an absent one. Return nil for it.
TestScopesFromToken covers absent, single, multiple, form-encoded,
non-string, empty and whitespace-only scopes; the last two fail without
the change. It also brings the package to 100% statement coverage.
Fixes #1318