Settings flow does not respect the return_to with a `/settings` path
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 4/5
- Tempo stimato
- 3-5 giorni
- Idoneità per principianti
- 35/100
- Tipo di issue
- Bug
- Chiarezza
- Abbastanza chiara
- Stato di attività
- Ferma
- Ambito
- authentication
Direzione di ricerca
Non sono indicati file, test o punti di ingresso. Riproduci il flusso delle impostazioni con un dominio personalizzato, un percorso relativo dell’interfaccia delle impostazioni e un return_to che punti a un URL contenente /settings; traccia il modo in cui l’invio delle impostazioni gestisce questo valore. Il lavoro è completato quando l’invio reindirizza all’URL return_to fornito invece di rimanere nella pagina delle impostazioni.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Preflight checklist
- I could not find a solution in the existing issues, docs, nor discussions.
- I agree to follow this project's Code of Conduct.
- I have read and am following this repository's Contribution Guidelines.
- This issue affects my Ory Network project.
- I have joined the Ory Community Slack.
- I am signed up to the Ory Security Patch Newsletter.
Describe the bug
A settings flow containing a return_to with the /settings path causes return_to to be ignored in the settings submit flow. An example is when you have an application with the url https://app.example.com/settings the URL will look like so:
https://auth.example.com/sefl-service/settings/browser?return_to=https://app.example.com/settings.
The project config has the following:
Custom Domain: auth.example.com
Custom UI: ui.example.com
Settings URL: /settings
note: this only happens with Custom domains and not when developing locally through the Ory tunnel
Reproducing the bug
- Create a project
- Add custom domain
- Add your custom UI base URL
- Keep the settings UI as a relative path
/settings - Initiate a
settingsflow with the return_to query parameter set to a route containing/settingsin the path (https://app.example.com/settings) - Submit the settings flow and see it stay on the settings page.
Relevant log output
No response
Relevant configuration
No response
Version
latest
On which operating system are you observing this issue?
None
In which environment are you deploying?
None
Additional Context
No response
- Lingua principale
- Shell
- Stelle
- 96
- Fork
- 8
- Metriche di merge delle PR
- Nessuna PR unita negli ultimi 30g
Preparare l'ambiente
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di ory/network
-
bug
Difficoltà 4/5 3-5 giorni Idoneità per principianti 38/100
-
Updating native registration flow with OIDC ID token for existing identity returns breaking responseApertabug
Difficoltà 4/5 3-5 giorni Idoneità per principianti 35/100
-
Ory Account Experience (hosted UI) registration trait setup via creation of registration flowApertafeat
Difficoltà 5/5 Più di una settimana Idoneità per principianti 25/100
-
selfservice.flows.login.style reverts to identifier_first despite explicitly setting passwordApertabug
Difficoltà 4/5 3-5 giorni Idoneità per principianti 30/100
-
feat
Difficoltà 5/5 Più di una settimana Idoneità per principianti 35/100
Issue simili
-
type: bug
Difficoltà 2/5 1-3 ore Idoneità per principianti 67/100
catppuccin/kde#152 ·
-
update-request
Difficoltà 2/5 1-3 ore Idoneità per principianti 75/100
msys2/MINGW-packages#32008 ·
I maintainer di solito rispondono entro 1 giorno
-
bot-found bug priority: P3
Difficoltà 2/5 1-3 ore Idoneità per principianti 84/100
madenvel/KalinkaPlayer#179 ·
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 88/100
I maintainer di solito rispondono entro 1 giorno
-
documentation
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100