Skip to content

fix: relax oauthlib scope check so extra Discord scopes don't 500 - #418

Merged
jontyms merged 1 commit into
HackUCF:devfrom
jontyms:fix/discord-oauth-scope-relax
Sep 15, 2026
Merged

jontyms merged 1 commit into
HackUCF:devfrom
jontyms:fix/discord-oauth-scope-relax

Conversation

@jontyms

@jontyms jontyms commented Sep 15, 2026

Copy link
Copy Markdown
Member

Summary

  • /api/oauth/ was 500ing (seen in Sentry) because Discord's token response now grants applications.commands in addition to the requested identify email guilds.join scopes — likely tied to the bot registering slash commands.
  • oauthlib treats any scope mismatch, even a harmless superset, as fatal by default and raises it as an exception inside fetch_token().
  • The app never reads/relies on the granted OAuth scope, so this relaxes the check via OAUTHLIB_RELAX_TOKEN_SCOPE=1 instead of requiring an exact match.

Test plan

  • Log in via /discord/new/ and confirm the /api/oauth/ callback completes without a 500 even when Discord grants extra scopes.

🤖 Generated with Claude Code

Discord's token response has started granting "applications.commands"
alongside the requested "identify email guilds.join" scopes (likely
tied to the bot now registering slash commands). oauthlib treats any
scope mismatch, including a harmless superset, as fatal and raises it
as an exception during fetch_token(), which was crashing /api/oauth/
with a 500 (seen in Sentry). The app never reads the OAuth scope
itself, so relax the check via OAUTHLIB_RELAX_TOKEN_SCOPE instead of
requiring an exact match.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01ByV6ZkqrAFHoKdWhGZQAiK
@jontyms
jontyms merged commit 0626cb4 into HackUCF:dev Sep 15, 2026
8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant