Skip to content

Scopes Object should be optional? #513

Description

@dwhieb

The Security Scheme Object lists the Scopes Object as required. However, the OAuth 2.0 specification for the Access Token Scope allows the client to omit the scope parameter, as long as a default behavior is specified:

If the client omits the scope parameter when requesting authorization, the authorization server MUST either process the request using a pre-defined default value or fail the request indicating an invalid scope. The authorization server SHOULD document its scope requirements and default value (if defined).

In other places in the spec, the scope parameter is explicitly stated as optional.

Does this mean that the Scopes Object should be optional too? Or allowed to be empty?

I'm wondering because I'm implementing an API with the Implicit grant flow where there's only one scope. Since there's just the one, I didn't want to have to declare it explicitly.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions