diff --git a/src/auth/oauth.ts b/src/auth/oauth.ts index 66cf876..6be63ef 100644 --- a/src/auth/oauth.ts +++ b/src/auth/oauth.ts @@ -38,6 +38,8 @@ export function oauthClientSecret(): string { // Full set of permission scopes requested by the CLI. export const DEFAULT_SCOPES = [ + 'agent_tools:read', + 'agent_tools:write', 'analytics:export', 'analytics:read', 'api_keys:delete', @@ -62,6 +64,9 @@ export const DEFAULT_SCOPES = [ 'integrations:delete', 'integrations:read', 'integrations:write', + 'issues:delete', + 'issues:read', + 'issues:write', 'labels:delete', 'labels:read', 'labels:write', @@ -74,6 +79,8 @@ export const DEFAULT_SCOPES = [ 'oauth_clients:delete', 'oauth_clients:read', 'oauth_clients:write', + 'pages:delete', + 'pages:read', 'ratings:write', 'repositories:delete', 'repositories:read', diff --git a/test/oauth-client.test.ts b/test/oauth-client.test.ts index 6240635..d9b8cab 100644 --- a/test/oauth-client.test.ts +++ b/test/oauth-client.test.ts @@ -6,7 +6,22 @@ import assert from 'node:assert/strict'; delete process.env.POLYLANE_OAUTH_CLIENT_ID; delete process.env.POLYLANE_OAUTH_CLIENT_SECRET; -const { oauthClientId, oauthClientSecret } = await import('../src/auth/oauth'); +const { DEFAULT_SCOPES, oauthClientId, oauthClientSecret } = await import('../src/auth/oauth'); + +it('requests the issue, agent tool, and page scopes the CLI exposes', () => { + const scopes = new Set(DEFAULT_SCOPES.split(' ')); + for (const scope of [ + 'agent_tools:read', + 'agent_tools:write', + 'issues:delete', + 'issues:read', + 'issues:write', + 'pages:delete', + 'pages:read', + ]) { + assert.ok(scopes.has(scope), `${scope} is missing from CLI OAuth login`); + } +}); describe('oauth client resolution', () => { beforeEach(() => {