( needed: readonly string[] | undefined, granted: readonly string[] | undefined, )
| 183 | * (needed − granted), order-preserving. Empty when `granted` is a superset/equal |
| 184 | * or `needed` is empty. */ |
| 185 | export function missingScopes( |
| 186 | needed: readonly string[] | undefined, |
| 187 | granted: readonly string[] | undefined, |
| 188 | ): readonly string[] { |
| 189 | const want = normalizeScopes(needed ?? []); |
| 190 | if (want.length === 0) return []; |
| 191 | const have = new Set(normalizeScopes(granted ?? [])); |
| 192 | return want.filter((scope: string) => !have.has(scope)); |
| 193 | } |
| 194 | |
| 195 | /** The scopes a connection was actually GRANTED, parsed from its space-delimited |
| 196 | * `oauthScope` record. Empty for static creds / when the AS omitted scope. */ |
no test coverage detected