Skip to content

fix(server): return invalid_scope for a scope the client isn't allowed - #403

Merged
osanderson merged 1 commit into
mainfrom
fix/invalid-scope-error-code
Sep 27, 2026
Merged

osanderson merged 1 commit into
mainfrom
fix/invalid-scope-error-code

Conversation

@osanderson

@osanderson osanderson commented Sep 27, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

The PAR and CIBA backchannel-authentication endpoints answered a scope the client isn't allowed (an unregistered scope, or openid under Config.OAuthOnly) with invalid_request. client_credentials already used invalid_scope for the same check.

  • RFC 9126 §2.3: PAR uses "the appropriate error code" from RFC 6749 §5.2 / §4.1.2.1, both of which define invalid_scope for a requested scope that is "invalid, unknown, or malformed".
  • CIBA Core §13: lists invalid_scope for the backchannel authentication endpoint.

Both sites now return invalid_scope. A missing scope (CIBA) or a non-string scope in a request object is a malformed request and stays invalid_request.

Conformance impact: none. The OIDF suite (checked at 4bfcdf8) never sends a PAR or CIBA request with a disallowed scope.

Testing

  • The four server tests covering these paths (unregistered scope and OAuthOnly openid, at PAR and CIBA) now expect invalid_scope. The CIBA table keeps invalid_request for the missing and non-string cases.
  • fapitest's end-to-end PAR test (from feat(client): expose the server's OAuth error response on client.Error #402) now expects invalid_scope from the real server.
  • go test -race on server, fapitest and cmd, plus golangci-lint, are clean.

🤖 Generated with Claude Code

https://claude.ai/code/session_01GMAyPYDPGpfnwow3JLeooZ

The pushed authorization request and backchannel authentication
endpoints answered a scope the client isn't registered for (or openid
under OAuthOnly) with invalid_request, while client_credentials already
used invalid_scope. RFC 6749 §4.1.2.1 and §5.2, which RFC 9126 §2.3
defers to, and CIBA Core §13 all define invalid_scope for a requested
scope that is "invalid, unknown, or malformed". A missing or non-string
scope is a malformed request and stays invalid_request.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@osanderson
osanderson force-pushed the fix/invalid-scope-error-code branch from 02a816b to e1fd3f7 Compare September 27, 2026 15:10
@osanderson
osanderson marked this pull request as ready for review September 27, 2026 15:10
@codecov

codecov Bot commented Sep 27, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

@sonarqubecloud

Copy link
Copy Markdown

@osanderson
osanderson merged commit 02cf7e0 into main Sep 27, 2026
9 checks passed
@osanderson
osanderson deleted the fix/invalid-scope-error-code branch September 27, 2026 15:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant