// Telling "this session was granted before we asked for that permission" // apart from any other refusal. // // Shared, because more than one feature asks the PDS for something a session // minted under an older `oauth/client-metadata.json` was never granted: the // feedback form writes a discussion record, and the labeler list reads the // account's preferences. /** * Whether a failed call means the session predates the scope it needed. * * Asking the session instead is not possible even in principle: the * authorization server expands `include:` into the permissions the set * holds before minting the token, so the granted scope never contains the * string that was requested, and the set's members are only known over there. * So the call is attempted and the PDS is what says no — a missing permission * comes back as `ScopeMissingError` naming the exact scope it wanted. */ export function isScopeError(err: unknown): boolean { const e = err as { error?: unknown; message?: unknown } | null const name = typeof e?.error === 'string' ? e.error : '' const message = typeof e?.message === 'string' ? e.message : '' return /scope/i.test(name) || /\bscope\b/i.test(message) }