diff --git a/crates/http/src/auth/oauth/registration.rs b/crates/http/src/auth/oauth/registration.rs index c14e3a7..310f240 100644 --- a/crates/http/src/auth/oauth/registration.rs +++ b/crates/http/src/auth/oauth/registration.rs @@ -270,13 +270,17 @@ impl ClientRegistrationHandler for Server { false }; - // Check if the account is allowed to override client registration - if self - .access_token(account_id) - .await - .caused_by(trc::location!())? - .build() - .has_permission(Permission::OAuthClientOverride) + // Check if the account is allowed to override client registration. + // inbuxa: only while setting up or recovering, when the recovery + // administrator signs in before any client is registered (contract C-5) + let registry = self.registry(); + if (registry.is_bootstrap_mode() || registry.is_recovery_mode()) + && self + .access_token(account_id) + .await + .caused_by(trc::location!())? + .build() + .has_permission(Permission::OAuthClientOverride) { return Ok(None); } diff --git a/crates/types/src/branding.rs b/crates/types/src/branding.rs index 353e171..be62261 100644 --- a/crates/types/src/branding.rs +++ b/crates/types/src/branding.rs @@ -81,7 +81,7 @@ fn legacy_setting(name: &str, is_set: impl Fn(&str) -> bool) -> Option { #[macro_export] macro_rules! brand_version { () => { - "2026.9.29" + "2026.9.29.1" }; }