commit 0b995184993af12cbb3012cccf245efa75679e8d
parent ff9a50fbfd214b425d4a7b03cbfe1202d8932821
Author: Christian Grothoff <christian@grothoff.org>
Date: Wed, 23 Sep 2026 14:40:04 +0200
kyclogic: treat an OAuth2 access_denied as a failed KYC process
Challenger now reports a validation the user can no longer pass this
way; it used to end up as an internal error.
Issue: https://bugs.taler.net/n/11740
Signed-off-by: Christian Grothoff <christian@grothoff.org>
Diffstat:
1 file changed, 5 insertions(+), 0 deletions(-)
diff --git a/src/kyclogic/plugin_kyclogic_oauth2.c b/src/kyclogic/plugin_kyclogic_oauth2.c
@@ -1719,6 +1719,11 @@ oauth2_proof (void *cls,
"unauthorized_client"))
ph->status = TALER_KYCLOGIC_STATUS_FAILED;
else if (0 == strcasecmp (err,
+ "access_denied"))
+ /* The provider refused authorization for good, e.g. challenger
+ after the user exhausted all attempts to prove their address. */
+ ph->status = TALER_KYCLOGIC_STATUS_FAILED;
+ else if (0 == strcasecmp (err,
"temporarily_unavailable"))
ph->status = TALER_KYCLOGIC_STATUS_PENDING;
else