fix: don't reject offline_accessscope

This commit is contained in:
Elias Schneider
2026-06-26 14:43:22 +02:00
parent cf54786cc3
commit 2ed703540d
3 changed files with 19 additions and 2 deletions
+17
View File
@@ -57,6 +57,23 @@ test('Authorize new client', async ({ page }) => {
);
});
test('Authorize client requesting offline_access scope', async ({ page }) => {
const oidcClient = oidcClients.immich;
const urlParams = createUrlParams(oidcClient);
urlParams.set('scope', 'openid profile email offline_access');
await page.goto(`/authorize?${urlParams.toString()}`);
// offline_access is a valid OIDC scope: the flow must reach the consent screen rather than
// being rejected with invalid_scope (offline_access itself has no displayable scope item)
await expectScopes(page, ['Email', 'Profile']);
const callbackUrl = await expectCallbackRedirect(page, oidcClient.callbackUrl, () =>
page.getByRole('button', { name: 'Sign in' }).click()
);
expect(callbackUrl.searchParams.get('code')).toBeTruthy();
expect(callbackUrl.searchParams.get('error')).toBeNull();
});
test('Authorize new client while not signed in', async ({ page }) => {
const oidcClient = oidcClients.immich;
const urlParams = createUrlParams(oidcClient);