| @@ -93,22 +93,8 @@ | ||
| 93 | 93 | |
| 94 | 94 | // Filter scopes to only allowed ones. |
| 95 | 95 | $filtered_scopes = $client->filter_scopes( Scope::validate( $scopes ) ); |
| 96 | 96 | |
| 97 | - /* | |
| 98 | - * Nothing the client asked for is allowed to it. Refusing here is what RFC 6749 ยง4.1.2.1 | |
| 99 | - * calls for, and it stops an empty grant from being minted: Token::create() would run the | |
| 100 | - * empty set back through Scope::validate(), which answers with the read-only default, so | |
| 101 | - * the client would end up holding `read` it was never granted. | |
| 102 | - */ | |
| 103 | - if ( empty( $filtered_scopes ) ) { | |
| 104 | - return new \WP_Error( | |
| 105 | - 'invalid_scope', | |
| 106 | - \__( 'The requested scopes are not allowed for this client.', 'activitypub' ), | |
| 107 | - array( 'status' => 400 ) | |
| 108 | - ); | |
| 109 | - } | |
| 110 | - | |
| 111 | 97 | // Generate the code. |
| 112 | 98 | $code = self::generate_code(); |
| 113 | 99 | $code_hash = self::hash_code( $code ); |
| 114 | 100 | $expires_at = \time() + self::EXPIRATION; |