fix(client): preserve scopes across authorization retries - #2448
Open
mattzcarey wants to merge 4 commits into
Open
mattzcarey wants to merge 4 commits into
mattzcarey wants to merge 4 commits into
Claude / Claude Code Review
completed
Jul 7, 2026 in 20m 33s
Code review found 1 important issue
Found 3 candidates, confirmed 2. See review comments for details.
Details
| Severity | Count |
|---|---|
| 🔴 Important | 1 |
| 🟡 Nit | 1 |
| 🟣 Pre-existing | 0 |
| Severity | File:Line | Issue |
|---|---|---|
| 🔴 Important | packages/client/src/client/auth.ts:186-194 |
forceReauthorization over-triggers when token response omitted scope, bypassing refresh on routine 401 |
Annotations
Check failure on line 194 in packages/client/src/client/auth.ts
claude / Claude Code Review
forceReauthorization over-triggers when token response omitted scope, bypassing refresh on routine 401
handleOAuthUnauthorized computes forceReauthorization = isStrictScopeSuperset(unionScope, tokens?.scope) with no guard for the case where the stored token has no scope field — which RFC 6749 §5.1 permits (and many ASes do) when granted == requested. Since the transports now thread accumulated _scope/challenge scope into ctx.scope on every 401, an ordinary access-token expiry then bypasses the working refresh token and forces interactive re-authorization (or throws UnauthorizedError), a regressio
Loading