From c4a6f0830e181948b6e2970e8ec1ff487d791ff3 Mon Sep 17 00:00:00 2001 From: Pedro Igor Date: Tue, 5 May 2020 17:56:39 -0300 Subject: [PATCH] [KEYCLOAK-14076] - Authorization context not always considering scope when checking permission --- core/src/main/java/org/keycloak/AuthorizationContext.java | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/core/src/main/java/org/keycloak/AuthorizationContext.java b/core/src/main/java/org/keycloak/AuthorizationContext.java index a78bd63801..566be8e9cd 100644 --- a/core/src/main/java/org/keycloak/AuthorizationContext.java +++ b/core/src/main/java/org/keycloak/AuthorizationContext.java @@ -69,7 +69,7 @@ public class AuthorizationContext { } } - if (current != null) { + if (current != null && scopeName == null) { if (current.getName().equals(resourceName)) { return true; }