do not automatically add groups to scope if using OPENID to handle groups w/ burnettk (#2212)

Co-authored-by: jasquat <jasquat@users.noreply.github.com>
This commit is contained in:
jasquat 2025-01-08 17:22:03 -05:00 committed by GitHub
parent cffaa09ba0
commit 005de8a5ec
No known key found for this signature in database
GPG Key ID: B5690EEEBB952194

View File

@ -118,12 +118,6 @@ def _set_up_open_id_scopes(app: Flask) -> None:
)
if os.environ.get("SPIFFWORKFLOW_BACKEND_OPEN_ID_SCOPES") is None:
scopes = app.config["SPIFFWORKFLOW_BACKEND_OPENID_SCOPE"].split(" ")
if (
os.environ.get("SPIFFWORKFLOW_BACKEND_OPEN_ID_SCOPES") is None
and app.config["SPIFFWORKFLOW_BACKEND_OPEN_ID_IS_AUTHORITY_FOR_USER_GROUPS"]
and "groups" not in scopes
):
scopes.append("groups")
app.config["SPIFFWORKFLOW_BACKEND_OPEN_ID_SCOPES"] = scopes