Conversation
EhabY
force-pushed
the
fix/oauth-scopes
branch
3 times, most recently
from
September 29, 2026 11:56
36cea00 to
b799b1a
Compare
Servers that enforce OAuth2 scopes rejected GET /users/me right after the token exchange, so OAuth login always failed. The same gap broke resolving a workspace by owner and name, which `coder ssh`, start, update, ping, speedtest and support bundle all do, and stop builds were refused outright. Request coder:workspaces.operate and coder:workspaces.access (which also grant organization_member:read, required for shared workspaces and not requestable on its own), workspace:create for `coder start` dry-runs when a workspace must update, and user:read. Verified against v2.25 through v2.37 and current main. Fixes VSC-24
Calls every Coder API method and stream the extension uses with a DEFAULT_OAUTH_SCOPES token against coder-preview, on changes to the scope or probe list and nightly. A unit test finds those methods in src/ with the type checker and fails when one has no probe. test/scopes/compose.yaml runs the same deployment locally.
EhabY
force-pushed
the
fix/oauth-scopes
branch
from
September 30, 2026 12:51
b799b1a to
329435a
Compare
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes VSC-24
Problem
With scope enforcement (coder/coder, next release after 2.37), OAuth login failed right after the token exchange:
GET /users/meneedsuser:read. An audit against a live server found more gaps with the same root cause:user:read) breaks remote SSH, ping, speedtest, support bundle,coder startandcoder update.user:read(owner lookup), and stop builds needworkspace:stop.organization_member:read, which is only grantable through thecoder:workspaces.*composites.coder startdry-runs a build when a workspace must update first (workspace:create).Fix
Verified with a real OAuth grant on v2.25.3, v2.27.11, v2.30.9, v2.34.11, v2.37.3 and current main. Released servers ignore requested scopes, so nothing changes there. Stored sessions with the old scopes fail the existing coverage check and re-authenticate.
Size
src/oauth/constants.tschanges.test/scopes/and the unit metatest), plus 7 lines updating existing OAuth fixtures.test:scopesscript, CONTRIBUTING.md).Tests
test/unit/oauth/scopeProbes.test.ts(unit, every PR, ~2s): uses the TypeScript checker to find everyCoderApirequest or stream method referenced insrc/, including throughPick<CoderApi, …>and structural interfaces. It fails if one has no probe, or if a probe/exemption is stale.test/scopes/(pnpm test:scopes): runs every probe inprobes.tswith a token limited toDEFAULT_OAUTH_SCOPES.deployment.tssets up a fresh deployment: an owner, a member, a coder-provider-only template, the member's workspace, and an owner workspace shared with the member.CoderApi. Streams that authorize per message must deliver one.test/scopes/compose.yaml: Postgres pluscoder-preview, used by CI and locally (see CONTRIBUTING.md):.github/workflows/oauth-scopes.yaml: runs when the scopes ortest/scopes/**change, and nightly to catch server-side changes before they ship.With the old scopes, 9 of 25 probes fail, each with the server's reason:
getAuthenticatedUserGET /users/me: 404user:readgetWorkspaceByOwnerAndNameGET /users/member/workspace/own: 404user:readgetWorkspaceByOwnerAndName (shared)GET /users/admin/workspace/shared: 404organization_member:read)getWorkspaceBuildByNumberGET /users/member/workspace/own/builds/1: 404user:readstopWorkspacePOST …/builds: 403 You do not have permission to stop this workspaceworkspace:stopstopWorkspace (shared)workspace:stopstartWorkspacePOST …/builds: 400 Unable to validate parameters: Failed to fetch workspace owneruser:readstartWorkspace (shared)organization_member:read)coder start dry-runPOST /templateversions/…/dry-run: 404workspace:createKnown gap: inbox notifications need
inbox_notification:read, which no public scope grants, so the server closes the socket on the first notification. Fixed server-side in coder/coder#30176.🤖 Generated with Claude Code