# How to get user's scope from a hub-managed service?

**URL:** <https://discourse.jupyter.org/t/how-to-get-users-scope-from-a-hub-managed-service/24489>\
**Category:** JupyterHub\
**Tags:** jupyterhub, help-wanted\
**Created:** [March 13, 2024, 1:10pm UTC](https://discourse.jupyter.org/t/how-to-get-users-scope-from-a-hub-managed-service/24489 "2024-03-13T13:10:01Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![trungleduc](https://yyz1.discourse-cdn.com/flex031/user_avatar/discourse.jupyter.org/trungleduc/32/12753_2.png) [@trungleduc](https://discourse.jupyter.org/u/trungleduc)\
**Post date:** [March 13, 2024, 1:10pm UTC](https://discourse.jupyter.org/t/how-to-get-users-scope-from-a-hub-managed-service/24489/1 "2024-03-13T13:10:01Z")

</div>

Hi all,

I’m converting this plugin [GitHub - plasmabio/tljh-repo2docker: Plugin for The Littlest JupyterHub to build multiple user environments with repo2docker](https://github.com/plasmabio/tljh-repo2docker) into a hub service.  
I follow the documentation here ([Scopes in JupyterHub — JupyterHub documentation](https://jupyterhub.readthedocs.io/en/stable/rbac/scopes.html#custom-scopes)) to create an admin scope for my service:

```python
#jupyterhub_config.py

c.JupyterHub.custom_scopes = {
    "custom:admin:tljh_repo2docker": {
        "description": "Admin access to myservice",
    },
}

c.JupyterHub.load_roles = [
    {
        "name": 'service-admin',
        "scopes":["custom:admin:tljh_repo2docker"],
        "users": ["alice"]
    }
]

```

Then in my handler, I fetch the user model with:

```python
class BaseHandler(HubOAuthenticated, web.RequestHandler):

    async def fetch_user(self) -> UserModel:
        user = self.current_user
        print(users)

```

The returned user model is just:

```auto
{
    "kind": "user",
    "groups": [],
    "admin": true,
    "name": "alice",
    "session_id": "e534e0fc9ffa48d28e524089dc8b9a42",
    "scopes": [
        "access:services!service=tljh_repo2docker",
        "read:users:groups!user=alice",
        "read:users:name!user=alice"
    ]
}

```

Do you know how can I get the custom scope that I assigned to user `alice`?

---

<div class="post-metadata">

**Author:** ![manics](https://yyz1.discourse-cdn.com/flex031/user_avatar/discourse.jupyter.org/manics/32/85_2.png) [@manics](https://discourse.jupyter.org/u/manics)\
**Post date:** [March 14, 2024, 3:16pm UTC](https://discourse.jupyter.org/t/how-to-get-users-scope-from-a-hub-managed-service/24489/2 "2024-03-14T15:16:00Z")

</div>

What scopes/permissions are assigned to your service?

> **[Services](https://jupyterhub.readthedocs.io/en/stable/reference/services.html#launching-a-hub-managed-service)**
>
> Definition of a Service: When working with JupyterHub, a Service is defined as a process that interacts with the Hub’s REST API. A Service may perform a specific action or task. For example, the fo...

---

<div class="post-metadata">

**Author:** ![minrk](https://yyz1.discourse-cdn.com/flex031/user_avatar/discourse.jupyter.org/minrk/32/13_2.png) [@minrk](https://discourse.jupyter.org/u/minrk)\
**Post date:** [March 14, 2024, 3:24pm UTC](https://discourse.jupyter.org/t/how-to-get-users-scope-from-a-hub-managed-service/24489/3 "2024-03-14T15:24:38Z")

</div>

The scopes requested by the service and ultimately assigned to oauth tokens when users visit the service are governed by [oauth\_client\_allowed\_scopes](https://github.com/jupyterhub/jupyterhub/blob/46c3548725c5b2c4224c726c636b5014c5672fae/examples/custom-scopes/jupyterhub_config.py#L10-L13). By default, it’s just enough to identify the user, not take any action on their behalf, but you can request more:

```python
c.JupyterHub.services = [
    {
        "name": "tljh-srvice",
        "oauth_client_allowed_scopes": [
            "custom:admin:tljh_repo2docker",
        ],
    },
]

```

Note: you will be granted a _subset_ of the requested scopes, so you still have to check what scopes a request is made with.

---

<div class="post-metadata">

**Author:** ![trungleduc](https://yyz1.discourse-cdn.com/flex031/user_avatar/discourse.jupyter.org/trungleduc/32/12753_2.png) [@trungleduc](https://discourse.jupyter.org/u/trungleduc)\
**Post date:** [March 14, 2024, 4:27pm UTC](https://discourse.jupyter.org/t/how-to-get-users-scope-from-a-hub-managed-service/24489/4 "2024-03-14T16:27:17Z")

</div>

Thank @manics and @minrk, updating the service config with `oauth_client_allowed_scopes` makes it work nicely!
