mirror of
https://github.com/galaxyproject/galaxy.git
synced 2026-09-24 16:30:27 +08:00
The Google secondary-AuthZ cloud-platform scope was gated on `backend.name is BACKENDS_NAME["google"]`, an identity comparison that is always False for the non-interned "google-openidconnect" string, so the scope was in fact never requested. Correcting that check would re-expose the original accumulation defect: the append mutated the backend's shared class-level DEFAULT_SCOPE, so the scope piled up on every login. Instead, request the cloud-platform scope the same way PR #22997 handles extra_scopes -- add it to the SCOPE setting at construction time and let social-core combine it with DEFAULT_SCOPE non-destructively. authenticate() no longer touches DEFAULT_SCOPE at all. Also drop the now-unused EXTRA_SCOPES config key; its only reader was removed when extra_scopes moved to the SCOPE setting.