Skip to content

fix(oauth): advertise only default scopes in protected resource metadata - #3251

Merged
SamMorrowDrums merged 2 commits into
mainfrom
sammorrowdrums-debug-oauth-metadata-scopes
Sep 8, 2026
Merged

fix(oauth): advertise only default scopes in protected resource metadata#3251
SamMorrowDrums merged 2 commits into
mainfrom
sammorrowdrums-debug-oauth-metadata-scopes

Conversation

@SamMorrowDrums

Copy link
Copy Markdown
Collaborator

Summary

  • advertise DefaultScopes from OAuth protected resource metadata instead of the full step-up scope catalog
  • keep non-default scopes such as delete_repo, workflow, and administrative scopes available through per-tool authorization challenges
  • strengthen the metadata regression test to assert the exact advertised scope list
  • document the default-versus-step-up behavior

Root cause

#3076 split the OAuth catalog into supported and default scopes, but intentionally left protected resource metadata wired to SupportedScopes. OAuth clients such as VS Code interpret scopes_supported as the initial authorization request, so production requested every optional scope at login.

Closes #3170

Keep the full OAuth scope catalog available for per-tool step-up challenges, but limit protected resource discovery to the lower-risk default grant.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@SamMorrowDrums
SamMorrowDrums requested a review from a team as a code owner September 8, 2026 18:49
Copilot AI balanced review requested due to automatic review settings September 8, 2026 18:49

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The regression test derives its expectation from production state and cannot detect accidental default-scope expansion.

Once you've addressed the issues Copilot identified, you can request another Copilot review.

Review tier: Balanced
Findings: 1 Medium severity

New issues introduced by this change (1)
Severity Finding
Medium severity pkg/​http/​oauth/​oauth_test.go — This expected value is the same package variable assigned to ScopesSupported, so an accidental…
What changed in this PR

Limits initial OAuth grants to default scopes while preserving step-up challenges for optional permissions, addressing #3170.

Changes:

  • Advertises DefaultScopes in protected-resource metadata.
  • Expands scope regression assertions.
  • Documents default and step-up scope behavior.
File Description
pkg/​http/​oauth/​oauth.go Uses default scopes in metadata.
pkg/​http/​oauth/​oauth_test.go Updates metadata and opt-in scope tests.
docs/​streamable-http.md Documents advertised default scopes.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread pkg/http/oauth/oauth_test.go Outdated
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
@SamMorrowDrums
SamMorrowDrums merged commit 7d13a7a into main Sep 8, 2026
19 checks passed
@SamMorrowDrums
SamMorrowDrums deleted the sammorrowdrums-debug-oauth-metadata-scopes branch September 8, 2026 18:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

VS Code remote GitHub MCP server requests delete_repo scope unconditionally on OAuth login, with no way to grant a subset

2 participants