From 1548401721f366b630f80b242120e8ccf9ce1d81 Mon Sep 17 00:00:00 2001 From: scanash00 Date: Sat, 24 Jan 2026 17:45:12 -0900 Subject: [PATCH] remove unnecessary RPC scopes from OAuth requests --- backend/internal/oauth/handler.go | 15 +++------------ 1 file changed, 3 insertions(+), 12 deletions(-) diff --git a/backend/internal/oauth/handler.go b/backend/internal/oauth/handler.go index be026bd..4ca29e9 100644 --- a/backend/internal/oauth/handler.go +++ b/backend/internal/oauth/handler.go @@ -147,10 +147,7 @@ func (h *Handler) HandleLogin(w http.ResponseWriter, r *http.Request) { "at.margin.reply " + "at.margin.like " + "at.margin.collection " + - "at.margin.collectionItem " + - "rpc:app.bsky.actor.searchActorsTypeahead?aud=* " + - "rpc:app.bsky.actor.getProfiles?aud=* " + - "rpc:com.atproto.identity.resolveHandle?aud=*" + "at.margin.collectionItem" parResp, state, dpopNonce, err := client.SendPAR(meta, handle, scope, dpopKey, pkceChallenge) if err != nil { @@ -257,10 +254,7 @@ func (h *Handler) HandleStart(w http.ResponseWriter, r *http.Request) { "at.margin.reply " + "at.margin.like " + "at.margin.collection " + - "at.margin.collectionItem " + - "rpc:app.bsky.actor.searchActorsTypeahead?aud=* " + - "rpc:app.bsky.actor.getProfiles?aud=* " + - "rpc:com.atproto.identity.resolveHandle?aud=*" + "at.margin.collectionItem" parResp, state, dpopNonce, err := client.SendPAR(meta, req.Handle, scope, dpopKey, pkceChallenge) if err != nil { @@ -517,10 +511,7 @@ func (h *Handler) HandleClientMetadata(w http.ResponseWriter, r *http.Request) { "at.margin.reply " + "at.margin.like " + "at.margin.collection " + - "at.margin.collectionItem " + - "rpc:app.bsky.actor.searchActorsTypeahead?aud=* " + - "rpc:app.bsky.actor.getProfiles?aud=* " + - "rpc:com.atproto.identity.resolveHandle?aud=*", + "at.margin.collectionItem", "token_endpoint_auth_method": "private_key_jwt", "token_endpoint_auth_signing_alg": "ES256", "dpop_bound_access_tokens": true, -- 2.51.2