Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Granted scope = none #163

Open
lcmaas opened this issue Mar 17, 2018 · 0 comments
Open

Granted scope = none #163

lcmaas opened this issue Mar 17, 2018 · 0 comments

Comments

@lcmaas
Copy link

lcmaas commented Mar 17, 2018

On the Scopes and Launch Context page, one of the example granted scopes is

none The authoriztion (sic) server chose to not grant any of the requested scopes.

If no scopes at all are granted (even some minimal "default" scope), then access has been effectively denied, and this should be communicated as such, e.g. as an access_denied error in the authorization response.

I suggest that the notes column for this row be modified to add something like "In the case that none of the requested scopes are granted, the authorization server will respond with an error, e.g. access_denied."

@lcmaas lcmaas changed the title should an empty scopes list be permitted? Granted scope = none Mar 30, 2018
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant