Skip to content

docs(admin): clarify OAuth2 tokens stay full-access behind proxies - #15731

Open
whoalin1 wants to merge 1 commit into
nextcloud:masterfrom
whoalin1:docs/oauth2-proxy-still-full-token
Open

whoalin1 wants to merge 1 commit into
nextcloud:masterfrom
whoalin1:docs/oauth2-proxy-still-full-token

Conversation

@whoalin1

@whoalin1 whoalin1 commented Oct 7, 2026 •

Copy link
Copy Markdown

Summary

Closes #1858

Security considerations already say tokens have full account access. Add an explicit note that fronting an app with something like oauth2_proxy does not reduce that scope: Nextcloud still issues a privileged Bearer token.

Test plan

  • Docs build for admin_manual/configuration_server/oauth2.rst
  • New paragraph under Security considerations mentions reverse proxy / oauth2_proxy

AI disclosure

This PR was drafted with the help of AI coding assistants (Cursor agents / LLM-based tools), including the description. I am responsible for it and happy to rework anything that doesn't fit.

All commits carry an Assisted-by: Cursor:grok-4.7 trailer.

Assisted-by: Cursor:grok-4.7
Signed-off-by: whoalin1 <[email protected]>
@whoalin1
whoalin1 force-pushed the docs/oauth2-proxy-still-full-token branch from 65fd472 to c1515fc Compare October 9, 2026 14:10

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Oauth2 Security considerations, vague?

1 participant