Wrong redirect when using self-hosted Kratos
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 3/5
- Tempo stimato
- 1-2 giorni
- Idoneità per principianti
- 38/100
- Tipo di issue
- Bug
- Chiarezza
- Abbastanza chiara
- Stato di attività
- Ferma
- Stack tecnologico
- nextjs, typescript
- Ambito
- authentication, frontend
Direzione di ricerca
Inizia in packages/nextjs/src/utils/rewrite.ts, nella logica di matching collegata, quindi riproduci un flusso usando la configurazione Kratos self-hosted e domini di autenticazione e applicazione differenti. Determina il comportamento di reindirizzamento previsto per gli URL UI configurati, aggiungi o aggiorna una copertura mirata se il repository la fornisce e verifica che quel flusso non ricada più erroneamente sull’URL del backend.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Hello!
I'm not sure if I am doing something wrong, but it seems there is an assumption here that may not be correct in cases of self-hosted Kratos:
https://github.com/ory/elements/blob/fdabadf8cb2e0ec4fd9286a5277516f8fd69aa0c/packages/nextjs/src/utils/rewrite.ts#L32C1-L32C62
In my Kratos config, I have:
kratos:
kratos:
config:
serve:
public:
base_url: https://auth.example.com
cors:
allowed_origins:
- http://localhost:3042
- https://auth.example.com
selfservice:
default_browser_return_url: https://example.com
allowed_return_urls:
- http://localhost:3042/*
- https://example.com/*
methods:
webauthn:
config:
rp:
id: example.com
origin: https://example.com:443/auth/login
flows:
error:
ui_url: https://example.com/error
settings:
ui_url: https://example.com/settings
recovery:
ui_url: https://example.com/auth/recovery
verification:
ui_url: https://example.com/auth/verification
after:
default_browser_return_url: https://example.com
logout:
after:
default_browser_return_url: https://example.com
login:
ui_url: https://example.com/auth/login
registration:
ui_url: https://example.com/auth/registration
Every time I start a flow, I get redirected to the UI URLs specified in the config, as-is.
In the linked code above, we can see it tries to match the base URL (let's say https://auth.example.com with the redirect https://example.com/auth/login). Of course, this do not match, it gives up and returns the URL as-is from the backend. It seems a bit weird to me that Ory HAS to be hosted on the same domain as the actual app handling the flows. I suppose this is something specific to the hosted version of Kratos/Ory services, and I also suppose the headers passed are supposed to mitigate this issue, but they do not have any effects in the self-hosted version, it seems.
I'm absolutely open to making a PR if required; I just want to make sure there was no oversight on my side first!
Thanks a lot.
- Lingua principale
- TypeScript
- Stelle
- 187
- Fork
- 79
- Metriche di merge delle PR
- Nessuna PR unita negli ultimi 30g
Preparare l'ambiente
- Nessun Dockerfile né file Docker Compose
- Ha un modello di pull request
- Leggi la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di ory/elements
-
Needs Triage
Difficoltà 2/5 1-3 ore Idoneità per principianti 70/100
-
enhancement
Difficoltà 3/5 1-2 giorni Idoneità per principianti 72/100
-
good first issue help wanted upstream
Difficoltà 2/5 1-3 ore Idoneità per principianti 45/100
-
good first issue help wanted upstream
Difficoltà 3/5 1-2 giorni Idoneità per principianti 25/100
-
Add React-only examplesApertaNeeds Triage
Difficoltà 3/5 1-2 giorni Idoneità per principianti 52/100
Tutte le issue di ory/elements
Issue simili
-
awaiting-response bug needs-triage
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
wildcard/caro#1562 · 1 commento ·
I maintainer di solito rispondono entro 3 giorni
-
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 72/100
supadata-ai/mcp#27 ·
-
content
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
cosimochellini/one-piece-zero-spoiler#516 ·
I maintainer di solito rispondono entro 1 giorno
-
bug
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
capricorn86/happy-dom#2485 ·
I maintainer di solito rispondono entro 2 giorni
-
lane: fast
Difficoltà 2/5 1-3 ore Idoneità per principianti 62/100
unicef/adt-studio#946 ·
I maintainer di solito rispondono entro 2 giorni