According to the registered scopes at https://fedoraproject.org/wiki/Infrastructure/Authentication#pagure.io.2Fodcs, there are different scopes for various access points to the code, but I am unable to see any code for handling this. The only code I'm seeing is for validating a set of "required scopes" in global.
This code would definitely be in-scope for a security audit, so this code being absent halts the security audit on that part.
Metadata Update from @cqi: - Issue assigned to cqi
PR: https://pagure.io/odcs/pull-request/78
Metadata Update from @jkaluza: - Issue status updated to: Closed (was: Open)
This issue has been migrated to Fedora Forge: https://forge.fedoraproject.org/pungi/odcs/issues/67
Please continue any further discussion there.