Closed (fixed)
Project:
Simple OAuth (OAuth2) & OpenID Connect
Version:
8.x-3.8
Component:
Code
Priority:
Critical
Category:
Bug report
Assigned:
Unassigned
Issue tags:
Reporter:
Created:
31 May 2018 at 05:58 UTC
Updated:
3 Aug 2022 at 16:13 UTC
Jump to comment: Most recent, Most recent file
Comments
Comment #2
rajandro commentedComment #3
e0ipsoI think that a failing test would help move this forward.
Comment #4
jyoti.singh commentedThere can be two solutions here :
Attaching a patch for the second method.
Comment #5
jyoti.singh commentedComment #6
msankhala commentedPatch looks good. Its good to have a test case for this to ensure that this does not break anything.
Comment #8
e0ipsoMerged! Thanks for the contribution.
Comment #9
e0ipsoSetting back to Active so someone can add tests to this.
Thanks!
Comment #10
el7cosmosThis prevent consumer with anoymous user (uid 0) to authenticate. There are some cases where a consumer didn't need an authenticated user, eg for client_credentials, and only looks for consumer roles.
Comment #11
e0ipso@el7cosmos will you be able to provide a patch to fix this?
Comment #12
el7cosmos@e0ipso I can limit the check to authenticated user only, is that enough?
Comment #14
e0ipsoThanks for the fix @el7cosmos!
Comment #16
Anonymous (not verified) commentedCould a new release be made which includes this patch? Upgrading to the latest dev version worked for me so that anonymous web service calls didn't log incorrect warnings, but it took me some time to figure out that this was what was causing the issue, since the ticket description isn't about that specifically. It would be nice if a new release was created so that people who usually install the latest stable version, like me, don't need to spend an hour or more tracking down the source of the errors.
In any case, though, thanks for the patch!
Comment #17
rajandro commentedComment #18
umed91 commentedI am still getting the above mentioned error and here is a simple patch to deny blocked users getting access token.
Comment #19
franckylfs commented@umed91, thanks for the patch, it works fine. I had to adapt it a bit to use email instead of username, but still.
I think you should reopen a new ticket referencing this one so that a follow up can be done