Commit 64ff5f2
Deny blank scopes in key_types mode instead of granting full access
Previously, allows_scope? treated blank scopes as "unrestricted",
allowing all operations. This is correct for simple mode (no key_types)
where scopes are opt-in, but dangerous when key_types with permission
ceilings are configured — a key with empty scopes would silently
bypass the entire scope enforcement system.
Now checks whether key_types mode is active: blank scopes means
"no access" in key_types mode, "unrestricted" in simple mode.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>1 parent 56e4ead commit 64ff5f2
2 files changed
+38
-5
lines changed| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
184 | 184 | | |
185 | 185 | | |
186 | 186 | | |
187 | | - | |
| 187 | + | |
| 188 | + | |
| 189 | + | |
| 190 | + | |
| 191 | + | |
| 192 | + | |
| 193 | + | |
188 | 194 | | |
189 | | - | |
190 | | - | |
191 | | - | |
192 | 195 | | |
193 | | - | |
| 196 | + | |
| 197 | + | |
| 198 | + | |
| 199 | + | |
| 200 | + | |
| 201 | + | |
| 202 | + | |
| 203 | + | |
194 | 204 | | |
195 | 205 | | |
196 | 206 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
45 | 45 | | |
46 | 46 | | |
47 | 47 | | |
| 48 | + | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
| 52 | + | |
| 53 | + | |
| 54 | + | |
| 55 | + | |
| 56 | + | |
| 57 | + | |
| 58 | + | |
| 59 | + | |
| 60 | + | |
| 61 | + | |
| 62 | + | |
| 63 | + | |
| 64 | + | |
| 65 | + | |
| 66 | + | |
| 67 | + | |
| 68 | + | |
| 69 | + | |
| 70 | + | |
48 | 71 | | |
49 | 72 | | |
50 | 73 | | |
| |||
0 commit comments