Auth0 Lock React - Insufficient Scope

Viewed 371

I try update the current user email but the Auth0 API response returns 403 error with this payload:

{
   "statusCode":403,
   "error":"Forbidden",
   "message":"You cannot update the following fields: email",
   "errorCode":"insufficient_scope"
}

But I pass the scope when I instantiate the lock.

this.lock = new Auth0Lock(clientId, domain, {
      auth: {
        redirectUrl: 'http://localhost:3000/login',
        responseType: 'token',
        params: {
          scope: 'openid email user_metadata app_metadata picture update:users'
        }
      },

My script to send the PATCH:

updateProfile(userId, data){
    const headers = {
      'Accept': 'application/json',
      'Content-Type': 'application/json',
      'Authorization': 'Bearer ' + this.getToken() //setting authorization header
    }
    // making the PATCH http request to auth0 api
    return fetch(`https://${this.domain}/api/v2/users/${userId}`, {
      method: 'PATCH',
      headers: headers,
      body: JSON.stringify(data)
    })
    .then(response => response.json())
    .then(newProfile => {
      this.setProfile(newProfile)
    }) //updating current profile
  }

Any ideas?

0 Answers
Related