oauth2 webhook: `granted_scopes` always empty for `authorization_code`
Nobody has claimed this yet.
Assessment
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Newbie friendliness
- 20/100
- Issue type
- Bug
- Clarity
- Needs clarification
- Activity status
- Stale
- Tech stack
- go
- Domain
- api, authentication, authorization
Research direction
Start with related issue #3620 and the OIDC token-hook authorization-code flow described here. Verify the webhook payload for an authorization-code flow and confirm that granted_scopes is included; note that the issue references an ongoing PR, #3970.
Written by the indexing model from the issue text.
Description
Preflight checklist
- I could not find a solution in the existing issues, docs, nor discussions.
- I agree to follow this project's Code of Conduct.
- [] I have read and am following this repository's Contribution Guidelines.
- I have joined the Ory Community Slack.
- [] I am signed up to the Ory Security Patch Newsletter.
Ory Network Project
No response
Describe the bug
Related to #3620
But when running OIDC flows with a token hook, the call does not include granted_scopes
Reproducing the bug
Same steps as #3620
Relevant log output
Relevant configuration
Version
2.3.0
On which operating system are you observing this issue?
None
In which environment are you deploying?
None
Additional Context
Working on a PR to address this #3970
- Dominant language
- Go
- Stars
- 17.6k
- Forks
- 1.6k
- PR merge metrics
- No merged PRs in 30d
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from ory/hydra
-
Needs Triage
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
-
feat
Difficulty 3/5 1-2 days Newbie friendliness 68/100
-
bug
Difficulty 3/5 1-2 days Newbie friendliness 64/100
-
Needs Triage
Difficulty 3/5 1-2 days Newbie friendliness 78/100
-
bug
Difficulty 4/5 3-5 days Newbie friendliness 52/100
Similar issues
-
optimization optimization:agents-md-curator
Difficulty 2/5 1-3 hours Newbie friendliness 86/100
githubnext/gh-aw-cao#13143 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
blinklabs-io/bursa#904 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
yanet-platform/ipfw-go#129 ·
-
bug confmap/provider/googlesecretmanagerprovider needs triage
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
open-telemetry/opentelemetry-collector-contrib#51273 · 2 comments ·
-
bug: AI Gateway client filter lists "Unknown" twice when NULL and literal Unknown clients coexist Openbug
Difficulty 2/5 1-3 hours Newbie friendliness 90/100