From 647366b11307facd35cfa76208baaaf4e4f3d699 Mon Sep 17 00:00:00 2001 From: PinkDev1 <5990@protonmail.com> Date: Thu, 2 Sep 2021 18:59:51 +0000 Subject: [PATCH 1/7] Added 155 scopes to oauth-oidc-scopes.txt All of these were manually gathered from: - https://developers.google.com/identity/protocols/oauth2/scopes - https://docs.github.com/en/developers/apps/building-oauth-apps/scopes-for-oauth-apps - https://api.slack.com/legacy/oauth-scopes - https://dev.fitbit.com/build/reference/web-api/oauth2/#scope --- Discovery/Web-Content/oauth-oidc-scopes.txt | 156 ++++++++++++++++++++ 1 file changed, 156 insertions(+) diff --git a/Discovery/Web-Content/oauth-oidc-scopes.txt b/Discovery/Web-Content/oauth-oidc-scopes.txt index c0ab19a..2094b5b 100644 --- a/Discovery/Web-Content/oauth-oidc-scopes.txt +++ b/Discovery/Web-Content/oauth-oidc-scopes.txt @@ -576,3 +576,159 @@ wiki-devops wordpress wx_open_id xwiki_groups +repo +repo:status +repo_deployment +public_repo +repo:invite +security_events +admin:repo_hook +write:repo_hook +read:repo_hook +admin:org +write:org +read:org +admin:public_key +write:public_key +read:public_key +admin:org_hook +gist +notifications +user +read:user +user:email +user:follow +delete_repo +write:discussion +read:discussion +write:packages +read:packages +delete:packages +admin:gpg_key +write:gpg_key +service.management +cloud-platform +webmasters +userinfo.email +openid +profile +email +admin.directory.customer +admin.directory.customer.readonly +admin.directory.device.chromeos +admin.directory.device.chromeos.readonly +admin.directory.device.mobile +admin.directory.device.mobile.action +admin.directory.device.mobile.readonly +admin.directory.domain +admin.directory.domain.readonly +admin.directory.group +admin.directory.group.member +admin.directory.group.member.readonly +admin.directory.group.readonly +admin.directory.orgunit +admin.directory.orgunit.readonly +admin.directory.resource.calendar +admin.directory.resource.calendar.readonly +admin.directory.rolemanagement +admin.directory.rolemanagement.readonly +admin.directory.user +admin.directory.user.alias +admin.directory.user.alias.readonly +admin.directory.user.readonly +admin.directory.user.security +admin.directory.userschema +admin.directory.userschema.readonly +cloud-platform +analytics +cloud-platform +source.full_control +source.read_only +source.read_write +devstorage.full_control +devstorage.read_only +devstorage.read_write +activity +heartrate +location +nutrition +profile +settings +sleep +social +weight +OAuth Scope +admin.analytics:read +admin.apps:read +admin.apps:write +admin.barriers:read +admin.barriers:write +admin.invites:read +admin.invites:write +admin.teams:read +admin.teams:write +admin.usergroups:read +admin.usergroups:write +admin.users:read +admin.users:write +authorizations:read +calls:read +calls:write +channels:history +channels:join +channels:manage +channels:read +channels:write +chat:write +chat:write:bot +chat:write:user +connections:write +conversations.connect:manage +conversations.connect:write +dnd:read +dnd:write +dnd:write:user +emoji:read +files:read +files:write +files:write:user +groups:history +groups:read +groups:write +identity.basic +identity.basic:user +identity:read:user +identity:read:user:user +im:history +im:read +im:write +links:write +mpim:history +mpim:read +mpim:write +pins:read +pins:write +reactions:read +reactions:write +reminders:read +reminders:read:user +reminders:write +reminders:write:user +remote_files:read +remote_files:share +remote_files:write +search:read +stars:read +stars:write +team:read +tokens.basic +usergroups:read +usergroups:write +users.profile:read +users.profile:write +users.profile:write:user +users:read +users:read.email +users:write +workflow.steps:execute + From bb991ad09af7417897d7ab249dfe14ee08224af7 Mon Sep 17 00:00:00 2001 From: PinkDev1 <5990@protonmail.com> Date: Thu, 2 Sep 2021 19:00:44 +0000 Subject: [PATCH 2/7] Sorted and removed duplicates from oauth-oidc-scopes.txt --- Discovery/Web-Content/oauth-oidc-scopes.txt | 377 ++++++++++---------- 1 file changed, 184 insertions(+), 193 deletions(-) diff --git a/Discovery/Web-Content/oauth-oidc-scopes.txt b/Discovery/Web-Content/oauth-oidc-scopes.txt index 2094b5b..de5c451 100644 --- a/Discovery/Web-Content/oauth-oidc-scopes.txt +++ b/Discovery/Web-Content/oauth-oidc-scopes.txt @@ -1,58 +1,74 @@ 1c -Active2 -AddressBookFields -AlcanceEmpleate -AllUserAttributes -Allgemeines_Template -ArgoCD -Atributi-forms -CARE-audience -CARE-service-audience -ClientConfig -CoffeeAndITRole -Gitlab -Groups -INBO_Java_Application -Jaeger-cicd-scope -Jenkins-azure -Jira -Jitsi -Linking_accounts -Mattermost -Nextcloud -Notificator -OpenID_PV_Basic_User_Info -PITMA -PSCUser -ROLE_ADMIN -ScopeLevel_JWTauthentication_REST_ExternalAuthServer -Security -Sonarqube -Strapi -UserManagement -Username -VNR -WPGroups aal abc account-audience accounts-api +Active2 +activity ad address address2 address3 address_ +AddressBookFields admin admin-aud admin-cli-audience admin-template +admin.analytics:read +admin.apps:read +admin.apps:write +admin.barriers:read +admin.barriers:write +admin.directory.customer +admin.directory.customer.readonly +admin.directory.device.chromeos +admin.directory.device.chromeos.readonly +admin.directory.device.mobile +admin.directory.device.mobile.action +admin.directory.device.mobile.readonly +admin.directory.domain +admin.directory.domain.readonly +admin.directory.group +admin.directory.group.member +admin.directory.group.member.readonly +admin.directory.group.readonly +admin.directory.orgunit +admin.directory.orgunit.readonly +admin.directory.resource.calendar +admin.directory.resource.calendar.readonly +admin.directory.rolemanagement +admin.directory.rolemanagement.readonly +admin.directory.user +admin.directory.user.alias +admin.directory.user.alias.readonly +admin.directory.user.readonly +admin.directory.user.security +admin.directory.userschema +admin.directory.userschema.readonly +admin.invites:read +admin.invites:write +admin.teams:read +admin.teams:write +admin.usergroups:read +admin.usergroups:write +admin.users:read +admin.users:write +admin:gpg_key +admin:org +admin:org_hook +admin:public_key +admin:repo_hook adminapi administrador advancedssoadmin-admin agroups aks +AlcanceEmpleate algoras-app-scope all +Allgemeines_Template +AllUserAttributes analytics analytics/query/data analytics/query/metadata @@ -64,6 +80,8 @@ apicallers apm app_version application +ArgoCD +Atributi-forms attribute1 attributes attributes_Json @@ -71,6 +89,7 @@ aud aud-mapper-scope audience auth-test-stagging-admin +authorizations:read auto-tmp1dlduuzf-admin auto-tmp1eaywbvt-admin auto-tmp1eleoycw-admin @@ -111,11 +130,23 @@ browsepy ca-assessments ca-config ca-profiles +calls:read +calls:write camunda-rest-api capital2-audience +CARE-audience +CARE-service-audience cdsi certificate changeUser +channels:history +channels:join +channels:manage +channels:read +channels:write +chat:write +chat:write:bot +chat:write:user chatbot cherry-lumen cila-admin @@ -124,11 +155,17 @@ client-role client-roles client-scope client_orchestrator_id +ClientConfig clientmapper +cloud-platform coffeeandit +CoffeeAndITRole collection-svc company_ids +connections:write contentApi +conversations.connect:manage +conversations.connect:write cpsadmins-admin cpsdevelopers-admin cpsotherusers-admin @@ -155,11 +192,19 @@ delete-after-date1623766895485-admin delete-after-date1623767154469-admin delete-after-date1623834887778-admin delete-after-date1623834980049-admin +delete:packages +delete_repo dev-bearer-client device:read device:write +devstorage.full_control +devstorage.read_only +devstorage.read_write dexcom displayname +dnd:read +dnd:write +dnd:write:user dns-admin-manager doc-test dossiers:checkKBO @@ -169,6 +214,7 @@ email email2 email3 email_ +emoji:read employee erp_api.hayleyhub.uk.all erp_credentials @@ -186,6 +232,9 @@ farhang-keycloak-proxy fat-jwt-data federated fhirUser +files:read +files:write +files:write:user firstname fiware-scope fixture-advancedssoadmin-admin @@ -216,6 +265,8 @@ fred_master_test_client_scope fullname gcp gcp-partner +gist +Gitlab given_name good-role good-service @@ -223,10 +274,15 @@ google grafana group group-scope +Groups groups +groups:history +groups:read +groups:write groups_as_list harbor haukesprog +heartrate hello-service home-jenkins home-users @@ -237,11 +293,23 @@ iam iam-open-broker-api-access id id_docs +identity.basic +identity.basic:user +identity:read:user +identity:read:user:user igneel +im:history +im:read +im:write +INBO_Java_Application indicagro-service ionic-demo +Jaeger-cicd-scope jaeger-dev-scope +Jenkins-azure jhipster +Jira +Jitsi jwt_client k8s_dev_resources k8s_dev_scope @@ -262,6 +330,9 @@ lastname launch launch/patient ldap_dn +Linking_accounts +links:write +location login manage-realm manageUsers @@ -272,6 +343,7 @@ masdata.company.list masdata.company.read masdata.company.update master-api +Mattermost md-buyline medapproved-audience mediawiki @@ -288,6 +360,9 @@ ml_app mobisis-students mobisis-teachers moderation +mpim:history +mpim:read +mpim:write mt2-audience mt2-ios-audience mt2-web-ui-audience @@ -297,8 +372,13 @@ nbf nbrownMapperService new_client_scope next-profile +Nextcloud normalized-openid notification +notifications +Notificator +nutrition +OAuth Scope oauth2_proxy_token oauth_client odoo @@ -314,6 +394,7 @@ oneadvanced-admin openid openid_client openid_connect +OpenID_PV_Basic_User_Info ops-services orchestrator.ops.all org-tmp1-admin @@ -371,6 +452,9 @@ phone phone2 phone3 phone_ +pins:read +pins:write +PITMA platform-cps-admin platform_audience pnum @@ -385,6 +469,8 @@ project:edit project:read project:view provider-portal-prod-audience +PSCUser +public_repo qa-abd-tuv-fvc-admin qa-aji-oeg-srm-admin qa-aws-uyu-osy-admin @@ -484,15 +570,35 @@ qa-zox-dpj-pzz-admin qa-zsl-blg-keb-admin qa-zzk-kzk-hht-admin rapier +reactions:read +reactions:write read +read:discussion +read:org +read:packages +read:public_key +read:repo_hook +read:user realm-management realm-management-audience registrar registry +reminders:read +reminders:read:user +reminders:write +reminders:write:user +remote_files:read +remote_files:share +remote_files:write +repo +repo:invite +repo:status +repo_deployment resource_access.cumulocity.roles restheart rm_client_scope role +ROLE_ADMIN role_list roles roles_ @@ -502,15 +608,30 @@ sap-adapter-admin schedule_zoom_meetings school-person-info scope_minio_mapper +ScopeLevel_JWTauthentication_REST_ExternalAuthServer +search:read +Security security-admin-console-audience +security_events service service-template +service.management services +settings sjpscope skb_scope +sleep slim-jwt-pv-info smart_city_profile +social +Sonarqube +source.full_control +source.read_only +source.read_write +stars:read +stars:write stone_code +Strapi students studioRGId subscription @@ -518,6 +639,7 @@ sudoers taka-org-ze-hej-c1-o1-admin taka-org-ze-hej-c1-o2-admin teachers +team:read test test-admin test-resources2-users-admin @@ -551,6 +673,7 @@ ti-api-admin-access tm-analytics-api-audience tm-analytics-api-service-audience tmh-gateway-audience +tokens.basic transport-scope tsr.admin tsr.write @@ -562,173 +685,41 @@ urn:kafka:cluster:kafka-cluster:cluster_action user user.read user/*.* -username -vehicle:read -vehicle:write -vero-permissions -warehouse_id -web-origins -web-origins_ -web-roles_(db-stage) -webhook -whoami -wiki-devops -wordpress -wx_open_id -xwiki_groups -repo -repo:status -repo_deployment -public_repo -repo:invite -security_events -admin:repo_hook -write:repo_hook -read:repo_hook -admin:org -write:org -read:org -admin:public_key -write:public_key -read:public_key -admin:org_hook -gist -notifications -user -read:user user:email user:follow -delete_repo -write:discussion -read:discussion -write:packages -read:packages -delete:packages -admin:gpg_key -write:gpg_key -service.management -cloud-platform -webmasters -userinfo.email -openid -profile -email -admin.directory.customer -admin.directory.customer.readonly -admin.directory.device.chromeos -admin.directory.device.chromeos.readonly -admin.directory.device.mobile -admin.directory.device.mobile.action -admin.directory.device.mobile.readonly -admin.directory.domain -admin.directory.domain.readonly -admin.directory.group -admin.directory.group.member -admin.directory.group.member.readonly -admin.directory.group.readonly -admin.directory.orgunit -admin.directory.orgunit.readonly -admin.directory.resource.calendar -admin.directory.resource.calendar.readonly -admin.directory.rolemanagement -admin.directory.rolemanagement.readonly -admin.directory.user -admin.directory.user.alias -admin.directory.user.alias.readonly -admin.directory.user.readonly -admin.directory.user.security -admin.directory.userschema -admin.directory.userschema.readonly -cloud-platform -analytics -cloud-platform -source.full_control -source.read_only -source.read_write -devstorage.full_control -devstorage.read_only -devstorage.read_write -activity -heartrate -location -nutrition -profile -settings -sleep -social -weight -OAuth Scope -admin.analytics:read -admin.apps:read -admin.apps:write -admin.barriers:read -admin.barriers:write -admin.invites:read -admin.invites:write -admin.teams:read -admin.teams:write -admin.usergroups:read -admin.usergroups:write -admin.users:read -admin.users:write -authorizations:read -calls:read -calls:write -channels:history -channels:join -channels:manage -channels:read -channels:write -chat:write -chat:write:bot -chat:write:user -connections:write -conversations.connect:manage -conversations.connect:write -dnd:read -dnd:write -dnd:write:user -emoji:read -files:read -files:write -files:write:user -groups:history -groups:read -groups:write -identity.basic -identity.basic:user -identity:read:user -identity:read:user:user -im:history -im:read -im:write -links:write -mpim:history -mpim:read -mpim:write -pins:read -pins:write -reactions:read -reactions:write -reminders:read -reminders:read:user -reminders:write -reminders:write:user -remote_files:read -remote_files:share -remote_files:write -search:read -stars:read -stars:write -team:read -tokens.basic usergroups:read usergroups:write +userinfo.email +UserManagement +Username +username users.profile:read users.profile:write users.profile:write:user users:read users:read.email users:write +vehicle:read +vehicle:write +vero-permissions +VNR +warehouse_id +web-origins +web-origins_ +web-roles_(db-stage) +webhook +webmasters +weight +whoami +wiki-devops +wordpress workflow.steps:execute - +WPGroups +write:discussion +write:gpg_key +write:org +write:packages +write:public_key +write:repo_hook +wx_open_id +xwiki_groups From 30b2c22d24b83091a7e58b09673a9bda5b36d13d Mon Sep 17 00:00:00 2001 From: PinkDev1 <5990@protonmail.com> Date: Thu, 2 Sep 2021 19:03:43 +0000 Subject: [PATCH 3/7] Removed scopes with nonces/temporary identifiers I left `delete-after-date1619708000534-admin` because it seems to have a UNIX timestamp, so it *might* be useful. --- Discovery/Web-Content/oauth-oidc-scopes.txt | 161 -------------------- 1 file changed, 161 deletions(-) diff --git a/Discovery/Web-Content/oauth-oidc-scopes.txt b/Discovery/Web-Content/oauth-oidc-scopes.txt index de5c451..42cc89f 100644 --- a/Discovery/Web-Content/oauth-oidc-scopes.txt +++ b/Discovery/Web-Content/oauth-oidc-scopes.txt @@ -90,37 +90,6 @@ aud-mapper-scope audience auth-test-stagging-admin authorizations:read -auto-tmp1dlduuzf-admin -auto-tmp1eaywbvt-admin -auto-tmp1eleoycw-admin -auto-tmp1eyrpmte-admin -auto-tmp1fwtubol-admin -auto-tmp1gvuthnr-admin -auto-tmp1hwrxaay-admin -auto-tmp1jlvrbjw-admin -auto-tmp1mdbjtvp-admin -auto-tmp1mecbtko-admin -auto-tmp1mifssjv-admin -auto-tmp1milmkwr-admin -auto-tmp1mzqfqgj-admin -auto-tmp1nrbcawi-admin -auto-tmp1nuyhigs-admin -auto-tmp1oyrevkh-admin -auto-tmp1qvriuim-admin -auto-tmp1rpvgrey-admin -auto-tmp1rrzhpea-admin -auto-tmp1srrjprn-admin -auto-tmp1venwzwf-admin -auto-tmp1wpuzvpj-admin -auto-tmp1xadvoeh-admin -auto-tmp1xclfncj-admin -auto-tmp1xuraork-admin -auto-tmp1xxmqfog-admin -auto-tmp1ybutssn-admin -auto-tmp1ykaivfj-admin -auto-tmp1zckkyea-admin -auto-tmp1zmrygef-admin -auto-tmp1zwksfza-admin avl avl_id base @@ -176,22 +145,6 @@ customer-control.itential.io data-gateway-api default delete-after-date1619708000534-admin -delete-after-date1619795027961-admin -delete-after-date1619795165592-admin -delete-after-date1621972703920-admin -delete-after-date1621972716128-admin -delete-after-date1621972716383-admin -delete-after-date1623242123562-admin -delete-after-date1623246901890-admin -delete-after-date1623593962776-admin -delete-after-date1623594025702-admin -delete-after-date1623611877516-admin -delete-after-date1623666528135-admin -delete-after-date1623666553016-admin -delete-after-date1623766895485-admin -delete-after-date1623767154469-admin -delete-after-date1623834887778-admin -delete-after-date1623834980049-admin delete:packages delete_repo dev-bearer-client @@ -223,10 +176,6 @@ etherpad event:edit eventival evotor -existing-tmp-org-brwswyvm-admin -existing-tmp-org-epvxnscj-admin -existing-tmp-org-gfvslisk-admin -existing-tmp-org-wgthnqmn-admin family_name farhang-keycloak-proxy fat-jwt-data @@ -245,18 +194,6 @@ fixture-enabled-org-admin fixture-existing-organization-admin fixture-existing-organization2-admin fixture-org1-multi-org-user-admin -fixture-org1ccpginj-admin -fixture-org1gbzrgvk-admin -fixture-org1ifdqigx-admin -fixture-org1jfwjivz-admin -fixture-org1lkidlon-admin -fixture-org1metnlsp-admin -fixture-org1niwxafr-admin -fixture-org1oiqyhty-admin -fixture-org1xukowuo-admin -fixture-org1xvteuwz-admin -fixture-org1ymfmoaq-admin -fixture-org1yuwikby-admin fixture-org2-multi-org-user-admin foobar forms-tenants @@ -471,104 +408,6 @@ project:view provider-portal-prod-audience PSCUser public_repo -qa-abd-tuv-fvc-admin -qa-aji-oeg-srm-admin -qa-aws-uyu-osy-admin -qa-bbq-bac-epf-admin -qa-bsp-gqv-vwb-admin -qa-bti-jum-vrl-admin -qa-bzu-tww-rfv-admin -qa-cbk-qog-pnx-admin -qa-czm-szv-ztg-admin -qa-dje-cxq-qir-admin -qa-dmx-jne-gnp-admin -qa-eqa-fgk-btr-admin -qa-ets-yln-zph-admin -qa-euw-nwd-ydp-admin -qa-eyg-chv-fys-admin -qa-fai-ynn-cwq-admin -qa-fcs-zlk-xmy-admin -qa-ffp-sln-qth-admin -qa-fgw-cvu-fla-admin -qa-fkk-ctw-iqy-admin -qa-fxh-jqr-sub-admin -qa-gam-vsw-nme-admin -qa-ggp-nwt-svq-admin -qa-gob-ogh-lzc-admin -qa-goc-lxt-zvv-admin -qa-gtn-coc-chx-admin -qa-gzg-koe-odf-admin -qa-hdh-fix-lul-admin -qa-hqb-bfl-rca-admin -qa-hum-pws-pmt-admin -qa-ikp-ttd-mdb-admin -qa-iwo-pvs-veh-admin -qa-iyi-ifh-kgb-admin -qa-iyv-wgo-tam-admin -qa-jnw-ejm-exu-admin -qa-jwh-lhb-pbt-admin -qa-jyi-rcn-jkc-admin -qa-kpf-bhe-ntb-admin -qa-krp-dqr-jch-admin -qa-kuj-xbe-pls-admin -qa-lcq-kvo-ara-admin -qa-lid-ybx-mfw-admin -qa-lix-ann-vxj-admin -qa-lro-vvv-shc-admin -qa-lvm-mqx-lnl-admin -qa-mdl-mnh-ufu-admin -qa-mpv-ldl-vxy-admin -qa-nbi-jwn-ewp-admin -qa-nea-xch-lxd-admin -qa-nee-fto-iux-admin -qa-nkv-drd-afq-admin -qa-nsu-vvu-tei-admin -qa-ogs-zdw-bml-admin -qa-oql-djg-sdm-admin -qa-ouq-odv-zek-admin -qa-owz-uxv-usd-admin -qa-ozu-bnq-ylj-admin -qa-pgh-slw-nav-admin -qa-pgr-xvc-brq-admin -qa-pkd-gma-mme-admin -qa-pny-qeq-itb-admin -qa-pzu-cbh-kwd-admin -qa-qdo-slj-gas-admin -qa-qgh-ldi-bel-admin -qa-qjd-hop-zro-admin -qa-qxk-sjt-xcd-admin -qa-qxs-wku-jcw-admin -qa-qzd-zax-juh-admin -qa-rdd-yfa-wiy-admin -qa-rmr-cwg-eru-admin -qa-rmx-wbv-ufm-admin -qa-rnz-omt-rvu-admin -qa-soz-kkj-auo-admin -qa-syc-rys-eat-admin -qa-tau-xpm-vel-admin -qa-tsf-mlh-tkp-admin -qa-tui-cuw-olf-admin -qa-tzy-qvw-ccs-admin -qa-ugt-kpo-fwu-admin -qa-upf-dhf-jfv-admin -qa-uro-sxu-hvq-admin -qa-vhr-toj-hxj-admin -qa-vjg-nxd-ktn-admin -qa-vuq-khj-pzo-admin -qa-wia-mge-xzk-admin -qa-wlu-chd-bna-admin -qa-wtm-tcn-rbs-admin -qa-xdk-aji-xsc-admin -qa-xqk-xlz-xrb-admin -qa-yph-wne-vol-admin -qa-ysv-iwf-qfj-admin -qa-yxh-obr-sxq-admin -qa-zfj-kfr-ivv-admin -qa-zjt-ecu-gee-admin -qa-zox-cia-dzu-admin -qa-zox-dpj-pzz-admin -qa-zsl-blg-keb-admin -qa-zzk-kzk-hht-admin rapier reactions:read reactions:write From e1c0693292c4f3db3505a040ae25e3a834b5360d Mon Sep 17 00:00:00 2001 From: PinkDev1 <5990@protonmail.com> Date: Thu, 2 Sep 2021 19:21:48 +0000 Subject: [PATCH 4/7] Added dropbox-app oauth scopes Scraped internally --- Discovery/Web-Content/oauth-oidc-scopes.txt | 26 +++++++++++++++++++++ 1 file changed, 26 insertions(+) diff --git a/Discovery/Web-Content/oauth-oidc-scopes.txt b/Discovery/Web-Content/oauth-oidc-scopes.txt index 42cc89f..1e55abd 100644 --- a/Discovery/Web-Content/oauth-oidc-scopes.txt +++ b/Discovery/Web-Content/oauth-oidc-scopes.txt @@ -562,3 +562,29 @@ write:public_key write:repo_hook wx_open_id xwiki_groups +account_info.write +account_info.read +files.metadata.write +files.metadata.read +files.content.write +files.content.read +sharing.write +sharing.read +file_requests.write +file_requests.read +contacts.write +contacts.read +team_info.read +team_data.member +team_data.team_space +files.team_metadata.write +files.permanent_delete +members.write +members.read +members.delete +groups.write +groups.read +sessions.modify +sessions.list +events.read + From e737a0f96baa078dacc38a3f7869eaa63da2e0eb Mon Sep 17 00:00:00 2001 From: PinkDev1 <5990@protonmail.com> Date: Thu, 2 Sep 2021 19:24:57 +0000 Subject: [PATCH 5/7] Added officially recognized OpenID scopes from https://openid.net/specs/openid-connect-core-1_0.html#ScopeClaims --- Discovery/Web-Content/oauth-oidc-scopes.txt | 25 +++++++++++++++++++++ 1 file changed, 25 insertions(+) diff --git a/Discovery/Web-Content/oauth-oidc-scopes.txt b/Discovery/Web-Content/oauth-oidc-scopes.txt index 1e55abd..d6917f0 100644 --- a/Discovery/Web-Content/oauth-oidc-scopes.txt +++ b/Discovery/Web-Content/oauth-oidc-scopes.txt @@ -587,4 +587,29 @@ groups.read sessions.modify sessions.list events.read +account_info.write +account_info.read +files.metadata.write +files.metadata.read +files.content.write +files.content.read +sharing.write +sharing.read +file_requests.write +file_requests.read +contacts.write +contacts.read +team_info.read +team_data.member +team_data.team_space +files.team_metadata.write +files.permanent_delete +members.write +members.read +members.delete +groups.write +groups.read +sessions.modify +sessions.list +events.read From 0bcb01ad6afe12f773904bd76588e13acb3f3ea3 Mon Sep 17 00:00:00 2001 From: PinkDev1 <5990@protonmail.com> Date: Thu, 2 Sep 2021 19:25:40 +0000 Subject: [PATCH 6/7] Sorted and removed duplicates --- Discovery/Web-Content/oauth-oidc-scopes.txt | 77 +++++++-------------- 1 file changed, 26 insertions(+), 51 deletions(-) diff --git a/Discovery/Web-Content/oauth-oidc-scopes.txt b/Discovery/Web-Content/oauth-oidc-scopes.txt index d6917f0..4c42a08 100644 --- a/Discovery/Web-Content/oauth-oidc-scopes.txt +++ b/Discovery/Web-Content/oauth-oidc-scopes.txt @@ -1,7 +1,10 @@ + 1c aal abc account-audience +account_info.read +account_info.write accounts-api Active2 activity @@ -132,6 +135,8 @@ CoffeeAndITRole collection-svc company_ids connections:write +contacts.read +contacts.write contentApi conversations.connect:manage conversations.connect:write @@ -175,12 +180,21 @@ esp-pact-client-scope etherpad event:edit eventival +events.read evotor family_name farhang-keycloak-proxy fat-jwt-data federated fhirUser +file_requests.read +file_requests.write +files.content.read +files.content.write +files.metadata.read +files.metadata.write +files.permanent_delete +files.team_metadata.write files:read files:write files:write:user @@ -213,6 +227,8 @@ group group-scope Groups groups +groups.read +groups.write groups:history groups:read groups:write @@ -284,6 +300,9 @@ Mattermost md-buyline medapproved-audience mediawiki +members.delete +members.read +members.write membership merchantAccesses mesh7-gk-scope @@ -456,7 +475,11 @@ service service-template service.management services +sessions.list +sessions.modify settings +sharing.read +sharing.write sjpscope skb_scope sleep @@ -479,6 +502,9 @@ taka-org-ze-hej-c1-o1-admin taka-org-ze-hej-c1-o2-admin teachers team:read +team_data.member +team_data.team_space +team_info.read test test-admin test-resources2-users-admin @@ -562,54 +588,3 @@ write:public_key write:repo_hook wx_open_id xwiki_groups -account_info.write -account_info.read -files.metadata.write -files.metadata.read -files.content.write -files.content.read -sharing.write -sharing.read -file_requests.write -file_requests.read -contacts.write -contacts.read -team_info.read -team_data.member -team_data.team_space -files.team_metadata.write -files.permanent_delete -members.write -members.read -members.delete -groups.write -groups.read -sessions.modify -sessions.list -events.read -account_info.write -account_info.read -files.metadata.write -files.metadata.read -files.content.write -files.content.read -sharing.write -sharing.read -file_requests.write -file_requests.read -contacts.write -contacts.read -team_info.read -team_data.member -team_data.team_space -files.team_metadata.write -files.permanent_delete -members.write -members.read -members.delete -groups.write -groups.read -sessions.modify -sessions.list -events.read - From 61c5f5a018f95b7faae43a25081a1e598bc0b0eb Mon Sep 17 00:00:00 2001 From: PinkDev1 <5990@protonmail.com> Date: Mon, 18 Oct 2021 01:36:33 +0000 Subject: [PATCH 7/7] Added a couple of scopes https://infosecwriteups.com/how-did-i-earned-6000-from-tokens-and-scopes-in-one-day-12f95c6bf8aa?source=rss----7b722bfd1b8d---4&gi=1e1df8e602a6 --- Discovery/Web-Content/oauth-oidc-scopes.txt | 2 ++ 1 file changed, 2 insertions(+) diff --git a/Discovery/Web-Content/oauth-oidc-scopes.txt b/Discovery/Web-Content/oauth-oidc-scopes.txt index 4c42a08..a30d56a 100644 --- a/Discovery/Web-Content/oauth-oidc-scopes.txt +++ b/Discovery/Web-Content/oauth-oidc-scopes.txt @@ -133,6 +133,8 @@ cloud-platform coffeeandit CoffeeAndITRole collection-svc +company:operations +company:support company_ids connections:write contacts.read