镜像站点 · 本页由第三方 GitHub 只读镜像提供,非 GitHub 官方站点,不接受任何登录或凭据输入。前往 github.com
Skip to content

fix(oauth): request the scopes the extension and CLI actually need - #1138

Open
EhabY wants to merge 1 commit into
mainfrom
fix/oauth-request-scopes
Open

EhabY wants to merge 1 commit into
mainfrom
fix/oauth-request-scopes

Conversation

@EhabY

@EhabY EhabY commented Oct 6, 2026

Copy link
Copy Markdown
Collaborator

Fixes VSC-24

Split out of #1128, which now holds only the live-server scope suite and is stacked on this PR.

Problem

Servers that enforce OAuth scopes (from 2.38) refuse the extension right after sign-in: GET /users/me needs user:read. An audit against a live server (#1128) found more gaps with the same cause:

  • Resolving a workspace by owner/name needs user:read. Without it, remote SSH, ping, speedtest, support bundle, coder start and coder update break.
  • Start builds need user:read (owner lookup), and stop builds need workspace:stop.
  • Workspaces shared by another user need organization_member:read, which only the coder:workspaces.* composites grant.
  • coder start dry-runs a build when a workspace must update first (workspace:create).
  • Inbox notifications need inbox_notification:read (fix: let scoped tokens list and mark inbox notifications read coder#30176).

Fix

coder:workspaces.operate coder:workspaces.access workspace:create user:read user:read_personal
  • inbox_notification:read is requested only when the server lists it in scopes_supported. Servers reject the whole request over an unknown scope, and release/2.38 doesn't offer it yet. Sessions without it stay valid and pick it up at the next sign-in.
  • When the server returns no scope, the extension stores coder:all. Only servers that ignore scopes do that, and they grant everything, so later scope changes no longer sign their users out. The stored value is used only by hasRequiredScopes; it is never sent to the server.
  • Logout revokes tokens even when their scopes are outdated. Before this, the refresh token stayed valid on the server.
  • Sessions granted coder:all are accepted.

Everyone signed in with OAuth signs in again once. Their stored sessions carry the old list, which no longer covers the required scopes. The CHANGELOG says so.

Size

181 additions and 68 deletions in 9 files:

Tests

  • Unit tests cover:
    • the optional scope being requested or omitted based on scopes_supported
    • revocation of tokens with outdated scopes
    • coder:all sessions
    • storing coder:all when the server returns no scope
  • Live-server coverage of every request is in test(oauth): check OAuth scopes against a live server #1128.

🤖 Generated with Claude Code

@linear-code

linear-code Bot commented Oct 6, 2026

Copy link
Copy Markdown

VSC-24

Servers that enforce OAuth scopes (from 2.38) refused the extension right
after sign-in: `/users/me` needs `user:read`. Request what the extension
and the CLI it runs need: the `coder:workspaces.operate` and
`coder:workspaces.access` composites, `workspace:create`, `user:read` and
`user:read_personal`.

Request `inbox_notification:read` only when the server lists it in
`scopes_supported`, since servers reject unknown scopes and 2.38 does not
offer it yet.

Store `coder:all` when the server returns no scope, as servers that ignore
scopes grant everything, so later scope changes do not sign their users
out. Sessions stored with the old list sign in again once.

Revoke tokens on logout even when their scopes are outdated, and accept
sessions granted `coder:all`.
@EhabY
EhabY force-pushed the fix/oauth-request-scopes branch from c9eff9e to e5d637a Compare October 7, 2026 08:45

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant