Skip to content

fix(client): preserve scopes across authorization retries - #2448

Open
mattzcarey wants to merge 4 commits into
mainfrom
fix/sep-2350-scope-accumulation
Open

mattzcarey wants to merge 4 commits into
mainfrom
fix/sep-2350-scope-accumulation

fix: address PR #2448 review feedback

e87cd73
Select commit
Loading
Failed to load commit list.
Claude / Claude Code Review completed Jul 7, 2026 in 20m 33s

Code review found 1 important issue

Found 3 candidates, confirmed 2. See review comments for details.

Details

Severity Count
🔴 Important 1
🟡 Nit 1
🟣 Pre-existing 0
Severity File:Line Issue
🔴 Important packages/client/src/client/auth.ts:186-194 forceReauthorization over-triggers when token response omitted scope, bypassing refresh on routine 401

Annotations

Check failure on line 194 in packages/client/src/client/auth.ts

See this annotation in the file changed.

@claude claude / Claude Code Review

forceReauthorization over-triggers when token response omitted scope, bypassing refresh on routine 401

handleOAuthUnauthorized computes forceReauthorization = isStrictScopeSuperset(unionScope, tokens?.scope) with no guard for the case where the stored token has no scope field — which RFC 6749 §5.1 permits (and many ASes do) when granted == requested. Since the transports now thread accumulated _scope/challenge scope into ctx.scope on every 401, an ordinary access-token expiry then bypasses the working refresh token and forces interactive re-authorization (or throws UnauthorizedError), a regressio