From 47db07dbc0d8f0396c3d67496a786568c189f887 Mon Sep 17 00:00:00 2001 From: Jian-Min Lin Date: Fri, 12 Jun 2026 07:08:10 +0800 Subject: [PATCH] chore(oauth): trim DCR scope comment per review feedback Shortens the inline comment per review feedback on #25958. Co-Authored-By: Claude Opus 4.8 (1M context) --- backend/open_webui/utils/oauth.py | 8 ++------ 1 file changed, 2 insertions(+), 6 deletions(-) diff --git a/backend/open_webui/utils/oauth.py b/backend/open_webui/utils/oauth.py index d1aeaec1a7..dfddd487e4 100644 --- a/backend/open_webui/utils/oauth.py +++ b/backend/open_webui/utils/oauth.py @@ -437,12 +437,8 @@ async def get_oauth_client_info_with_dynamic_client_registration( resource = resource_metadata.resource # Prefer the resource-specific scopes from the Protected Resource Metadata - # (RFC 9728 Section 2) over the Authorization Server's scopes_supported - # (RFC 8414 Section 2). The AS scopes_supported is a full catalog of every - # scope the server can grant across all resources, whereas the PRM - # scopes_supported represents what this specific resource requires - making - # it the correct, least-privilege source. This mirrors the static-credentials - # flow (see #24690). + # (RFC 9728) over the AS's full scopes_supported catalog, for least + # privilege. Mirrors the static-credentials flow (#24690). if resource_metadata.scopes_supported: oauth_client_metadata.scope = ' '.join(resource_metadata.scopes_supported)