Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Stop validating that returned scope matches requested scope #116

Merged
merged 2 commits into from Jun 16, 2023

Conversation

ragalie
Copy link
Contributor

@ragalie ragalie commented Jun 15, 2023

We've determined that this does not constitute a security issue in Shopify's context and we'd like the flexibility to return a different set of scopes in the future.

@ragalie ragalie self-assigned this Jun 15, 2023
We've determined that this does not constitute a security issue in
Shopify's context and we'd like the flexibility to return a different
set of scopes in the future.
@bernardoamc
Copy link

Extra context:

Merchants can only grant scopes to an app that they have access to themselves, this means that an account takeover on a merchant account with lower privileges won't result in privilege escalation when installing an app.

@ragalie ragalie merged commit d948ddc into master Jun 16, 2023
4 checks passed
@ragalie ragalie deleted the remove-scope-check branch June 16, 2023 17:07
@ragalie ragalie mentioned this pull request Jun 16, 2023
@shopify-shipit shopify-shipit bot temporarily deployed to rubygems June 19, 2023 13:29 Inactive
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

3 participants