PluginProbe
ActivityPub / 9.2.1
ActivityPub v9.2.1
9.3.1 9.3.0 9.2.2 9.2.1 9.2.0 9.1.0 9.0.2 9.0.1 9.0.0 8.3.0 8.2.1 8.2.0 8.1.1 1.0.5 1.0.6 1.0.7 1.0.8 1.0.9 1.1.0 1.2.0 1.3.0 2.0.0 2.0.1 2.1.0 2.1.1 All 160 releases
← All changes | includes/oauth/class-authorization-code.php +0 -14 9.3.0 → 9.2.1 View file →
@@ -93,22 +93,8 @@
93 93
94 94 // Filter scopes to only allowed ones.
95 95 $filtered_scopes = $client->filter_scopes( Scope::validate( $scopes ) );
96 96
97 - /*
98 - * Nothing the client asked for is allowed to it. Refusing here is what RFC 6749 ยง4.1.2.1
99 - * calls for, and it stops an empty grant from being minted: Token::create() would run the
100 - * empty set back through Scope::validate(), which answers with the read-only default, so
101 - * the client would end up holding `read` it was never granted.
102 - */
103 - if ( empty( $filtered_scopes ) ) {
104 - return new \WP_Error(
105 - 'invalid_scope',
106 - \__( 'The requested scopes are not allowed for this client.', 'activitypub' ),
107 - array( 'status' => 400 )
108 - );
109 - }
110 -
111 97 // Generate the code.
112 98 $code = self::generate_code();
113 99 $code_hash = self::hash_code( $code );
114 100 $expires_at = \time() + self::EXPIRATION;