You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
This PR fixes handling of the user_code query parameter in gotoUrl during the OAuth2 authorization process. Old implementation does not check if the query parameter already exists. As a result, the DuplicateRequestParameterValidator throws a DuplicateRequestParameterException for URL with existing user_code query parameter.
I'm not sure if my flow was correct. The user_code attribute should probably not be part of the OAuth2 authorize request. I will convert the PR to a draft and do more detailed analysis later.
I'm not sure if my flow was correct. The user_code attribute should probably not be part of the OAuth2 authorize request. I will convert the PR to a draft and do more detailed analysis later.
You are probably right. It does not make sense to actually have user_code part of the /oauth2/authorize request. When the OAuth2 client can open user agent (e.g. in case of mobile app), it can surely handle custom redirect URI (app links / universal links). Device code flow with its user_code attribute is when the browser is being opened on a different device. The only case when the user_code can be used like this is for example when the whole authorization URL is being e-mailed... not sure if that is a valid use case.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR fixes handling of the
user_codequery parameter ingotoUrlduring the OAuth2 authorization process. Old implementation does not check if the query parameter already exists. As a result, theDuplicateRequestParameterValidatorthrows aDuplicateRequestParameterExceptionfor URL with existinguser_codequery parameter.