• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

ory / fosite / 1518 / 1
71%
master: 71%

Build:
DEFAULT BRANCH: master
Ran 09 May 2020 11:14AM UTC
Files 97
Run time 6s
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

09 May 2020 11:12AM UTC coverage: 71.447% (+0.05%) from 71.399%
1518.1

push

travis-ci

web-flow
fix: do not issue refresh tokens to clients who cannot use it (#430)

No prior discussion, but this is somewhat related to #370, which makes it possible for clients to be issued a refresh token without requesting a scope.

There may be clients which may not be allowed to use the refresh_token grant type, but which will currently be issued a refresh token during the authorization code flow. Disallowing the refresh_token grant type might be particularly common when there are public clients (using this flow with PKCE).

It is impossible to use the issued refresh token when the client does not have the grant type, and no other client can use it either. It would be neater to avoid issuing refresh tokens that cannot be used.

3841 of 5376 relevant lines covered (71.45%)

71.41 hits per line

Source Files on job 1518.1
  • Tree
  • List 0
  • Changed 14
  • Source Changed 1
  • Coverage Changed 14
Coverage ∆ File Lines Relevant Covered Missed Hits/Line
  • Back to Build 1464
  • Travis Job 1518.1
  • 792670d0 on github
  • Prev Job for on master (#1512.1)
  • Next Job for on master (#1519.1)
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc