Redirect problem after login to refresh privileged session
Nadie ha tomado este issue todavía.
Evaluación
- Dificultad
- 4/5
- Tiempo estimado
- 3-5 días
- Aptitud para principiantes
- 25/100
- Tipo de issue
- Error
- Claridad
- Necesita aclaración
- Estado de actividad
- Estancado
- Stack tecnológico
- docker-compose
- Área
- authentication
Línea de trabajo
El issue no menciona archivos ni pruebas; comienza reproduciendo el flujo de la sesión privilegiada desde la página de configuración personalizada, utilizando la URL return_to documentada y la llamada GetSelfServiceSettingsFlow. Sigue la redirección del login y verifica que volver a la configuración complete la acción privilegiada sin el error de método GET ni requerir que el usuario la repita.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
Preflight checklist
- I could not find a solution in the existing issues, docs, nor discussions.
- I agree to follow this project's Code of Conduct.
- I have read and am following this repository's Contribution Guidelines.
- This issue affects my Ory Cloud project.
- I have joined the Ory Community Slack.
- I am signed up to the Ory Security Patch Newsletter.
Describe the bug
When the user needs to login to refresh a privileged session (e.g. from the settings page), it is redirected from the current page to the login page with the following return_to url:
http://ory.domain.com/self-service/settings?flow=FLOW_ID
After a successful login, the login page should redirect the user to the address at return_to (above).
Redirecting the user there ends up in the settings page. Calling GetSelfServiceSettingsFlow at that stage provides a flow with the error below and the user needs to repeat the last action:
Unable to decode body because HTTP Request Method was "GET" but only [POST PUT PATCH] are supported.
We assume this is a bug and that at this stage we should have a settings flow updated after completing the operation the user tried to perform. We also tried to compare the settings flow from the first call and after the login, but they are pretty much the same, so no clue on what should be done differently.
Please advise.
Reproducing the bug
- Configure your Ory Session privileged timeout to a small interval (e.g. 30s)
- Go your custom kratos ui settings page
- Execute a privileged action (e.g. reveal backup recovery codes)
- Wait for redirect to login
- Enter the correct credentials
- Wait fo redirect back to settings
- The error message is shown and the privileged action is not executed
Relevant log output
No response
Relevant configuration
No response
Version
0.0.1-alpha.169
On which operating system are you observing this issue?
Windows
In which environment are you deploying?
Docker Compose
Additional Context
No response
- Lenguaje dominante
- Shell
- Estrellas
- 96
- Forks
- 8
- Métricas de merge de PR
- Sin PR fusionados en 30 d
Preparar el entorno
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de ory/network
-
bug
Dificultad 4/5 3-5 días Aptitud para principiantes 38/100
-
Updating native registration flow with OIDC ID token for existing identity returns breaking responseAbiertobug
Dificultad 4/5 3-5 días Aptitud para principiantes 35/100
-
Ory Account Experience (hosted UI) registration trait setup via creation of registration flowAbiertofeat
Dificultad 5/5 Más de una semana Aptitud para principiantes 25/100
-
selfservice.flows.login.style reverts to identifier_first despite explicitly setting passwordAbiertobug
Dificultad 4/5 3-5 días Aptitud para principiantes 30/100
-
feat
Dificultad 5/5 Más de una semana Aptitud para principiantes 35/100
Todos los issues de ory/network
Issues similares
-
type: bug
Dificultad 2/5 1-3 horas Aptitud para principiantes 67/100
catppuccin/kde#152 ·
-
update-request
Dificultad 2/5 1-3 horas Aptitud para principiantes 75/100
msys2/MINGW-packages#32008 ·
Los mantenedores suelen responder en 1 día
-
bot-found bug priority: P3
Dificultad 2/5 1-3 horas Aptitud para principiantes 84/100
madenvel/KalinkaPlayer#179 ·
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 88/100
Los mantenedores suelen responder en 1 día
-
[platform-assessment 2026-09]Abiertodocumentation
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100