-
Notifications
You must be signed in to change notification settings - Fork 6.2k
Open
Labels
status: waiting-for-triageAn issue we've not yet triagedAn issue we've not yet triagedtype: bugA general bugA general bug
Description
Describe the bug
If a registered client supporting the authorization_code has no scopes, and requires authorization consent.
When a client makes an authorization request decision, they see a consent screen with no scopes displayed (see screenshot).
If the user clicks "submit consent", an oauth2 error redirect happens, because it is expected that there is at least one scope consented to (source)
Expected behavior
I see three options:
- Disallow the "require consent + 0 scope" combination for clients
- Allow the combination but skip the consent screen
- Allow the combination, present the screen and allow the user to click "submit consent"
Screenshot

injae-kim, ryujungkyun and Khyojaeinjae-kim and ryujungkyun
Metadata
Metadata
Assignees
Labels
status: waiting-for-triageAn issue we've not yet triagedAn issue we've not yet triagedtype: bugA general bugA general bug