Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Check oauth2 authorization code redirect for exact 'code' query parameter #1777

Merged
merged 2 commits into from
Mar 22, 2024
Merged

Check oauth2 authorization code redirect for exact 'code' query parameter #1777

merged 2 commits into from
Mar 22, 2024

Conversation

layereight
Copy link
Contributor

@layereight layereight commented Mar 12, 2024

Description

Redirects during OAuth2 authorization code flow are only identified through a rather broad regex match for code in the redirect uri. The authorization process will fail for authorization servers offering a "multi-step" authorization that include intemediate redirects casually containing the keyword code in their uri.

This change checks the redirect for the distinct code query paramter as defined in the RFC

Contribution Checklist:

  • The pull request only addresses one issue or adds one feature.
  • The pull request does not introduce any breaking changes
  • I have added screenshots or gifs to help explain the change if applicable.
  • I have read the contribution guidelines.
  • Create an issue and link to the pull request.

Fixes #1778

@layereight layereight mentioned this pull request Mar 18, 2024
@helloanoop helloanoop merged commit 753ca43 into usebruno:main Mar 22, 2024
@helloanoop
Copy link
Contributor

Merged!

Thank you @layereight !

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

BUG: OAuth2 Authorization Code Flow fails for intermediate redirects
3 participants