Settings flow does not respect the return_to with a `/settings` path
Nadie ha tomado este issue todavía.
Evaluación
- Dificultad
- 4/5
- Tiempo estimado
- 3-5 días
- Aptitud para principiantes
- 35/100
- Tipo de issue
- Error
- Claridad
- Bastante claro
- Estado de actividad
- Estancado
- Área
- authentication
Línea de trabajo
No se especifican archivos, pruebas ni puntos de entrada. Reproduce el flujo de configuración con un dominio personalizado, una ruta relativa de la interfaz de configuración y un return_to que apunte a una URL que contenga /settings; rastrea cómo el envío de la configuración gestiona ese valor. Se considera terminado cuando el envío redirige a la URL return_to proporcionada en lugar de permanecer en la página de configuración.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
Preflight checklist
- I could not find a solution in the existing issues, docs, nor discussions.
- I agree to follow this project's Code of Conduct.
- I have read and am following this repository's Contribution Guidelines.
- This issue affects my Ory Network project.
- I have joined the Ory Community Slack.
- I am signed up to the Ory Security Patch Newsletter.
Describe the bug
A settings flow containing a return_to with the /settings path causes return_to to be ignored in the settings submit flow. An example is when you have an application with the url https://app.example.com/settings the URL will look like so:
https://auth.example.com/sefl-service/settings/browser?return_to=https://app.example.com/settings.
The project config has the following:
Custom Domain: auth.example.com
Custom UI: ui.example.com
Settings URL: /settings
note: this only happens with Custom domains and not when developing locally through the Ory tunnel
Reproducing the bug
- Create a project
- Add custom domain
- Add your custom UI base URL
- Keep the settings UI as a relative path
/settings - Initiate a
settingsflow with the return_to query parameter set to a route containing/settingsin the path (https://app.example.com/settings) - Submit the settings flow and see it stay on the settings page.
Relevant log output
No response
Relevant configuration
No response
Version
latest
On which operating system are you observing this issue?
None
In which environment are you deploying?
None
Additional Context
No response
- Lenguaje dominante
- Shell
- Estrellas
- 96
- Forks
- 8
- Métricas de merge de PR
- Sin PR fusionados en 30 d
Preparar el entorno
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de ory/network
-
bug
Dificultad 4/5 3-5 días Aptitud para principiantes 38/100
-
Updating native registration flow with OIDC ID token for existing identity returns breaking responseAbiertobug
Dificultad 4/5 3-5 días Aptitud para principiantes 35/100
-
Ory Account Experience (hosted UI) registration trait setup via creation of registration flowAbiertofeat
Dificultad 5/5 Más de una semana Aptitud para principiantes 25/100
-
selfservice.flows.login.style reverts to identifier_first despite explicitly setting passwordAbiertobug
Dificultad 4/5 3-5 días Aptitud para principiantes 30/100
-
feat
Dificultad 5/5 Más de una semana Aptitud para principiantes 35/100
Todos los issues de ory/network
Issues similares
-
type: bug
Dificultad 2/5 1-3 horas Aptitud para principiantes 67/100
catppuccin/kde#152 ·
-
update-request
Dificultad 2/5 1-3 horas Aptitud para principiantes 75/100
msys2/MINGW-packages#32008 ·
Los mantenedores suelen responder en 1 día
-
bot-found bug priority: P3
Dificultad 2/5 1-3 horas Aptitud para principiantes 84/100
madenvel/KalinkaPlayer#179 ·
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 88/100
Los mantenedores suelen responder en 1 día
-
[platform-assessment 2026-09]Abiertodocumentation
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100