do: {:error, :missing_scopes}
def validate(scopes, app_scopes, %Pleroma.User{is_admin: is_admin}) do
- if !is_admin && contains_admin_scopes?(scopes) do
- {:error, :user_is_not_an_admin}
- else
- validate_scopes_are_supported(scopes, app_scopes)
- end
+ validate_scopes_are_supported(scopes, app_scopes)
+ end
+
+ @spec filter_admin_scopes([String.t()], Pleroma.User.t()) :: [String.t()]
+ @doc """
+ Remove admin scopes for non-admins
+ """
+ def filter_admin_scopes(scopes, %Pleroma.User{is_admin: true}), do: scopes
+
+ def filter_admin_scopes(scopes, _user) do
+ drop_scopes = OAuthScopesPlug.filter_descendants(scopes, ["admin"])
+ Enum.reject(scopes, fn scope -> Enum.member?(drop_scopes, scope) end)
end
defp validate_scopes_are_supported(scopes, app_scopes) do