Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Fix mysql timing bug #863

Merged
merged 3 commits into from
May 20, 2018
Merged

Fix mysql timing bug #863

merged 3 commits into from
May 20, 2018

Conversation

aeneasr
Copy link
Member

@aeneasr aeneasr commented May 20, 2018

No description provided.

@aeneasr aeneasr force-pushed the fix-mysql-timing-bug branch from bf3a97b to 6564d71 Compare May 20, 2018 13:04
@aeneasr aeneasr force-pushed the fix-mysql-timing-bug branch from 6564d71 to 1db5e20 Compare May 20, 2018 13:13
Currently, authorization requests fail when a client is being granted scopes that the client is not allowed to request - after consent.

We should add an additional check that makes sure that the client isn't able to request scopes he isn't allowed to request before doing consent.

We should keep the check after consent as well to make sure he wasn't accidentally granted scopes he isn't allowed to request.

This patch resolves the addressed issue

Closes #776
@aeneasr aeneasr merged commit 7675144 into master May 20, 2018
@aeneasr aeneasr deleted the fix-mysql-timing-bug branch May 20, 2018 13:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant