Remove default scope from the Refresh Token Grant

This commit is contained in:
Andrew Millington 2017-11-06 21:23:52 +00:00
parent 093c7755fa
commit cc6eb63dd8

View File

@ -44,7 +44,7 @@ class RefreshTokenGrant extends AbstractGrant
// Validate request
$client = $this->validateClient($request);
$oldRefreshToken = $this->validateOldRefreshToken($request, $client->getIdentifier());
$scopes = $this->validateScopes($this->getRequestParameter('scope', $request, $this->defaultScope));
$scopes = $this->validateScopes($this->getRequestParameter('scope', $request));
// If no new scopes are requested then give the access token the original session scopes
if (count($scopes) === 0) {