Repository navigation
feat(identity): let extensions register their own UCP OAuth scopes - #250
Merged
Björn Meyer (BrocksiNet) merged 3 commits intoSep 25, 2026
Merged
Conversation
Sebastian Hölscher (HoelShare)
requested a review
from Björn Meyer (BrocksiNet)
September 22, 2026 11:27
Contributor
|
Should an omitted |
The grantable scopes were a private class constant on ShopwareIdentityLinkingAdapter, so a plugin adding a UCP capability of its own had no way to make its scope grantable: the authorization request threw `Unsupported OAuth scope`. A consent flow that catches that exception has already burned its one-time handle by then, so the buyer is told the authorization link expired -- indistinguishable from a real expiry, and two consent links were lost to it before the cause was found. UcpOAuthScopeRegistry now merges the plugin's own scopes with those returned by every service tagged `swag_agentic_commerce.ucp.oauth_scope_provider`, the same tagged-iterator mechanism the product-export providers already use. The adapter advertises the merged set in `scopes_supported` on /.well-known/oauth-authorization-server and validates against it, so an agent can discover a scope before requesting it. The three built-in scopes are unchanged, an empty scope request still expands to every supported scope, and an unregistered scope is still rejected -- now with the supported set named in the message, which is what made this hard to diagnose. AbstractUcpOAuthScopeProvider is the plugin's second public PHP extension point and is documented in docs/public-api-boundaries.md. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Expanding an empty scope to every registered scope meant installing an extension widened what an unchanged client that omits `scope` is granted. An omitted scope now gets the three core scopes, as before the extension point existed; an extension scope has to be requested by name. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Sebastian Hölscher (HoelShare)
force-pushed
the
claude/shopware-oauth-scope-extension-fce26c
branch
from
September 23, 2026 11:14
7e01ac2 to
0f90560
Compare
Contributor
Author
|
Good point Björn Meyer (@BrocksiNet). I've adjusted so only the core scopes are granted! |
Björn Meyer (BrocksiNet)
approved these changes
Sep 23, 2026
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Björn Meyer (BrocksiNet)
approved these changes
Sep 25, 2026
Björn Meyer (BrocksiNet)
deleted the
claude/shopware-oauth-scope-extension-fce26c
branch
September 25, 2026 07:05
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The grantable scopes were a private class constant on ShopwareIdentityLinkingAdapter, so a plugin adding a UCP capability of its own had no way to make its scope grantable: the authorization request threw
Unsupported OAuth scope. A consent flow that catches that exception has already burned its one-time handle by then, so the buyer is told the authorization link expired -- indistinguishable from a real expiry, and two consent links were lost to it before the cause was found.UcpOAuthScopeRegistry now merges the plugin's own scopes with those returned by every service tagged
swag_agentic_commerce.ucp.oauth_scope_provider, the same tagged-iterator mechanism the product-export providers already use. The adapter advertises the merged set inscopes_supportedon /.well-known/oauth-authorization-server and validates against it, so an agent can discover a scope before requesting it.The three built-in scopes are unchanged, an empty scope request still expands to every supported scope, and an unregistered scope is still rejected -- now with the supported set named in the message, which is what made this hard to diagnose.
AbstractUcpOAuthScopeProvider is the plugin's second public PHP extension point and is documented in docs/public-api-boundaries.md.