From ca6484c3562c82150151017e03ae1141e47c253c Mon Sep 17 00:00:00 2001 From: John Coffey Date: Tue, 29 Sep 2026 07:02:51 -0700 Subject: [PATCH] Honor the client registration override only in setup and recovery The recovery administrator signs in before any OAuth client is registered, so it needs to skip the registration check. Outside bootstrap and recovery mode, every account now signs in through a registered client and one of its redirect URIs. --- crates/http/src/auth/oauth/registration.rs | 18 +++++++++++------- 1 file changed, 11 insertions(+), 7 deletions(-) diff --git a/crates/http/src/auth/oauth/registration.rs b/crates/http/src/auth/oauth/registration.rs index c14e3a7..310f240 100644 --- a/crates/http/src/auth/oauth/registration.rs +++ b/crates/http/src/auth/oauth/registration.rs @@ -270,13 +270,17 @@ impl ClientRegistrationHandler for Server { false }; - // Check if the account is allowed to override client registration - if self - .access_token(account_id) - .await - .caused_by(trc::location!())? - .build() - .has_permission(Permission::OAuthClientOverride) + // Check if the account is allowed to override client registration. + // inbuxa: only while setting up or recovering, when the recovery + // administrator signs in before any client is registered (contract C-5) + let registry = self.registry(); + if (registry.is_bootstrap_mode() || registry.is_recovery_mode()) + && self + .access_token(account_id) + .await + .caused_by(trc::location!())? + .build() + .has_permission(Permission::OAuthClientOverride) { return Ok(None); }