Wrong redirect when using self-hosted Kratos
Nadie ha tomado este issue todavía.
Evaluación
- Dificultad
- 3/5
- Tiempo estimado
- 1-2 días
- Aptitud para principiantes
- 38/100
- Tipo de issue
- Error
- Claridad
- Bastante claro
- Estado de actividad
- Estancado
- Stack tecnológico
- nextjs, typescript
- Área
- authentication, frontend
Línea de trabajo
Comienza en packages/nextjs/src/utils/rewrite.ts, en la lógica de matching enlazada, y después reproduce un flujo usando la configuración de Kratos self-hosted y dominios de autenticación y aplicación diferentes. Determina el comportamiento de redirección esperado para las URL de UI configuradas, añade o actualiza cobertura específica si el repositorio la proporciona, y verifica que ese flujo ya no vuelva incorrectamente a la URL del backend.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
Hello!
I'm not sure if I am doing something wrong, but it seems there is an assumption here that may not be correct in cases of self-hosted Kratos:
https://github.com/ory/elements/blob/fdabadf8cb2e0ec4fd9286a5277516f8fd69aa0c/packages/nextjs/src/utils/rewrite.ts#L32C1-L32C62
In my Kratos config, I have:
kratos:
kratos:
config:
serve:
public:
base_url: https://auth.example.com
cors:
allowed_origins:
- http://localhost:3042
- https://auth.example.com
selfservice:
default_browser_return_url: https://example.com
allowed_return_urls:
- http://localhost:3042/*
- https://example.com/*
methods:
webauthn:
config:
rp:
id: example.com
origin: https://example.com:443/auth/login
flows:
error:
ui_url: https://example.com/error
settings:
ui_url: https://example.com/settings
recovery:
ui_url: https://example.com/auth/recovery
verification:
ui_url: https://example.com/auth/verification
after:
default_browser_return_url: https://example.com
logout:
after:
default_browser_return_url: https://example.com
login:
ui_url: https://example.com/auth/login
registration:
ui_url: https://example.com/auth/registration
Every time I start a flow, I get redirected to the UI URLs specified in the config, as-is.
In the linked code above, we can see it tries to match the base URL (let's say https://auth.example.com with the redirect https://example.com/auth/login). Of course, this do not match, it gives up and returns the URL as-is from the backend. It seems a bit weird to me that Ory HAS to be hosted on the same domain as the actual app handling the flows. I suppose this is something specific to the hosted version of Kratos/Ory services, and I also suppose the headers passed are supposed to mitigate this issue, but they do not have any effects in the self-hosted version, it seems.
I'm absolutely open to making a PR if required; I just want to make sure there was no oversight on my side first!
Thanks a lot.
- Lenguaje dominante
- TypeScript
- Estrellas
- 187
- Forks
- 80
- Métricas de merge de PR
- Sin PR fusionados en 30 d
Preparar el entorno
- Sin Dockerfile ni archivo de Docker Compose
- Tiene una plantilla de pull request
- Leer la guía de contribución
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de ory/elements
-
Needs Triage
Dificultad 2/5 1-3 horas Aptitud para principiantes 70/100
-
good first issue help wanted upstream
Dificultad 2/5 1-3 horas Aptitud para principiantes 45/100
-
good first issue help wanted upstream
Dificultad 3/5 1-2 días Aptitud para principiantes 25/100
-
Add React-only examplesAbiertoNeeds Triage
Dificultad 3/5 1-2 días Aptitud para principiantes 52/100
-
guessPotentiallyProxiedOrySdkUrl breaks flows in production behind a non-Vercel reverse proxyAbiertobug
Dificultad 4/5 3-5 días Aptitud para principiantes 45/100
Todos los issues de ory/elements
Issues similares
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 85/100
siyuan-note/siyuan#20040 ·
Los mantenedores suelen responder en 1 día
-
enhancement
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
RunestoneInteractive/rs#1574 ·
Los mantenedores suelen responder en 2 días
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 68/100
remotion-dev/remotion#11901 ·
Los mantenedores suelen responder en 1 día
-
Poll constructor throws for an uncached channel while resolving a message context-menu interactionAbiertobug need repro packages:discord.js
Dificultad 2/5 1-3 horas Aptitud para principiantes 82/100
discordjs/discord.js#11645 ·
Los mantenedores suelen responder en 3 días
-
🐞 bug
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
Sitecore/content-sdk#641 ·
Los mantenedores suelen responder en 2 días