fix(client): enforce OAuth scope token grammar - #44
Merged
Conversation
kauandotnet
force-pushed
the
codex/oauth-scope-token-grammar
branch
2 times, most recently
from
September 3, 2026 20:39
9223af1 to
255dde8
Compare
kauandotnet
force-pushed
the
codex/oauth-scope-token-grammar
branch
from
September 3, 2026 20:42
255dde8 to
f546bf3
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Enforces RFC 6749 ASCII NQCHAR scope-token grammar across OAuth discovery, authority normalization, authorization inputs, DCR responses, and token responses. Valid punctuation such as commas remains supported.\n\nAdds a shared exported bounded validator. Exchange responses inherit the pinned requested scope when scope is omitted. Refresh callers can bind the current effective scope; omission retains it, while explicit widening is rejected in both flows.\n\nRegression coverage includes quote, backslash, non-ASCII, bounds, omission, and widening.\n\nVerification: the full repository verify gate passes. ATTW used an isolated npm cache because the host default cache contains an unrelated permissions error.