fn approval_waived(services: &Services, redirect_uri: &str) -> boolExpand description
Whether the authorization code goes out without asking the user first.
Two conditions waive the prompt: the operator turned it off with
oidc_require_client_approval, or listed this redirect target in the
registration allowlist. Neither holds on a server running open dynamic
registration, where an attacker can register a client of their own and phish
an authorization link. An initial access token deliberately does not waive
it, since closing registration says nothing about the clients that were
already registered when it closed.