diff --git a/crates/didbot-agentd/src/bin/didbot-oauth.rs b/crates/didbot-agentd/src/bin/didbot-oauth.rs index 850e3376..d43c8477 100644 --- a/crates/didbot-agentd/src/bin/didbot-oauth.rs +++ b/crates/didbot-agentd/src/bin/didbot-oauth.rs @@ -45,8 +45,12 @@ account. --direct insists on it rather than trying the socket first. "; /// What an approval's answer says of the login it made, whichever mode it -/// came through: the scopes requested, then the scopes current policies -/// allow. +/// came through: the scopes requested, then the scopes the scope ceiling +/// allows. +/// +/// Named for the check that produced the second list. A token policy can +/// still refuse the exchange, and a write policy can still refuse a write a +/// listed scope covers. fn print_scopes(requested: &[String], granted: &[String]) { print!("{}", scope_block(requested, granted)); } @@ -59,9 +63,9 @@ fn scope_block(requested: &[String], granted: &[String]) -> String { block.push_str(&format!("* {}\n", printable(scope))); } if granted == requested { - block.push_str("Current policies allow these scopes:\n"); + block.push_str("The scope ceiling allows these scopes:\n"); } else { - block.push_str("Current policies only allow these scopes:\n"); + block.push_str("The scope ceiling allows only these scopes:\n"); } for scope in granted { block.push_str(&format!("* {}\n", printable(scope))); @@ -348,7 +352,7 @@ mod tests { block.contains(r"* repo:generic\u{1b}[2K\u{1b}[Aadmin"), "{block}" ); - assert!(block.contains("Current policies only allow these scopes:")); + assert!(block.contains("The scope ceiling allows only these scopes:")); } #[test] diff --git a/crates/didbot-serve/src/oauth/par.rs b/crates/didbot-serve/src/oauth/par.rs index 7d5670af..c02afefd 100644 --- a/crates/didbot-serve/src/oauth/par.rs +++ b/crates/didbot-serve/src/oauth/par.rs @@ -1087,7 +1087,10 @@ mod tests { .consume(&reference) .expect("the reference is live"); assert_eq!(pending.granted_scope.to_string(), "atproto"); - assert_eq!(record.requested.to_string(), "atproto repo:app.bsky.feed.post"); + assert_eq!( + record.requested.to_string(), + "atproto repo:app.bsky.feed.post" + ); } /// `plan/scope-policy.md`'s "log every scopedown", and the shape the diff --git a/crates/didbot-serve/src/routes.rs b/crates/didbot-serve/src/routes.rs index f23c92b7..e4da9a7b 100644 --- a/crates/didbot-serve/src/routes.rs +++ b/crates/didbot-serve/src/routes.rs @@ -1370,10 +1370,9 @@ fn authorize_error_response(err: crate::oauth::authorize::AuthorizeError) -> Res /// The heading is a placeholder, per this project's copywriting rule. The /// rest is plain labels over the attributes, which are the load-bearing part. /// -/// The page lists the scopes requested, then the scopes current policies -/// would allow if approved. Approving covers that second list, and the -/// ceiling is asked again at every use (`data-approves`, -/// `data-ceiling-checked`). +/// The page lists the scopes requested, then the scopes the scope ceiling +/// allows. Approving covers that second list, and the ceiling is asked again +/// at every use (`data-approves`, `data-ceiling-checked`). /// /// There is no form. Approving is `bot.did.approveAuthorization`, which /// takes the account's own agent token as `Credential::AgentSelf` — a @@ -1409,16 +1408,20 @@ fn authorize_page(pending: &crate::oauth::authorize::AuthorizePending) -> String .collect(); format!("