fix(permissions): preserve canonical granted scopes
This commit is contained in:
@@ -100,7 +100,12 @@ def expand_scopes(scopes: Iterable[str], *, include_unknown: bool = True) -> lis
|
|||||||
for alias in compatible_required_scopes(scope):
|
for alias in compatible_required_scopes(scope):
|
||||||
if alias != scope:
|
if alias != scope:
|
||||||
expanded.add(alias)
|
expanded.add(alias)
|
||||||
if include_unknown and not matched:
|
# Preserve explicitly granted scopes in the presentation set. A
|
||||||
|
# canonical module scope can still match its legacy compatibility
|
||||||
|
# alias when the providing module is not loaded; treating that match
|
||||||
|
# as proof that the original scope is known would otherwise replace
|
||||||
|
# the canonical grant with only the deprecated alias.
|
||||||
|
if include_unknown or scope in catalog:
|
||||||
expanded.add(scope)
|
expanded.add(scope)
|
||||||
return sorted(expanded)
|
return sorted(expanded)
|
||||||
|
|
||||||
|
|||||||
@@ -24,6 +24,12 @@ class PermissionCatalogContractTests(unittest.TestCase):
|
|||||||
self.assertIn("files:upload", scopes)
|
self.assertIn("files:upload", scopes)
|
||||||
self.assertIn("mail_servers:test", scopes)
|
self.assertIn("mail_servers:test", scopes)
|
||||||
|
|
||||||
|
def test_expand_scopes_preserves_explicit_canonical_scope_with_legacy_alias(self) -> None:
|
||||||
|
scopes = access_catalog.expand_scopes(("files:file:read",))
|
||||||
|
|
||||||
|
self.assertIn("files:file:read", scopes)
|
||||||
|
self.assertIn("files:read", scopes)
|
||||||
|
|
||||||
|
|
||||||
if __name__ == "__main__":
|
if __name__ == "__main__":
|
||||||
unittest.main()
|
unittest.main()
|
||||||
|
|||||||
Reference in New Issue
Block a user