AuthState callback isn't called if the redirect URI does not end with "/"
Nobody has claimed this yet.
Assessment
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Newbie friendliness
- 45/100
- Issue type
- Bug
- Clarity
- Mostly clear
- Activity status
- Stale
- Tech stack
- ios, objective-c
- Domain
- authentication, mobile
Research direction
Start with the AppAuth-iOS example project and reproduce the login flow on iOS 16 using a redirect URI without a trailing slash. Trace the redirect handling and AuthState callback path, comparing successful completion with cancellation. Done means the callback is invoked with either success or an error for the non-slash URI.
Written by the indexing model from the issue text.
Description
Describe the bug
I developed an app using OpenID Connect (on the Microsoft identity platform) and here is what I noticed: AuthState callback isn't called when the connection succeeds if the redirect URI doesn't end with "/". However, it is called whenever the connection process is interrupted (for example, if the "Cancel" button is tapped).
I finally found a solution when I read this issue comment: https://github.com/openid/AppAuth-iOS/issues/197#issuecomment-597212857. So it seems necessary to add "/" at the end of the redirect URI.
To Reproduce
Clone the example project of AppAuth-iOS and configure it with your own issuer, client ID and redirect URI. The redirect URI must not end with a "/". Launch the project, enter your login and password, and validate the connection. Then it correctly redirects to the app, but the callback isn't called.
Expected behavior
It should call the callback (either raising an error to report it or succeeding).
Environment
- Device: iPhone 14 (or any other device running iOS 16)
- OS: iOS 16
Additional context
This bug doesn't exist in the Android library (AppAuth-Android: https://github.com/openid/AppAuth-Android): the callback is always called, even though the redirect URI doesn't end with "/".
- Dominant language
- Objective-C
- Stars
- 2k
- Forks
- 868
- Avg merge
- 9d 20h
- Merged PRs (30d)
- 1
Getting set up
- No Dockerfile or Docker Compose file
- No pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from openid/AppAuth-iOS
-
enhancement
Difficulty 1/5 Under an hour Newbie friendliness 60/100
openid/AppAuth-iOS#908 ·
-
Difficulty 5/5 Over a week Newbie friendliness 35/100
openid/AppAuth-iOS#962 ·
-
enhancement triage
Difficulty 4/5 3-5 days Newbie friendliness 38/100
openid/AppAuth-iOS#953 ·
-
enhancement triage
Difficulty 4/5 3-5 days Newbie friendliness 45/100
openid/AppAuth-iOS#948 ·
-
bug
Difficulty 4/5 3-5 days Newbie friendliness 35/100
openid/AppAuth-iOS#932 · 1 comment ·
All issues in openid/AppAuth-iOS
Similar issues
-
api: remoteconfig
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
firebase/firebase-ios-sdk#16816 · 1 comment ·
Maintainers usually reply within 1 day
-
!
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
osmandapp/OsmAnd-iOS#5912 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-2 days Newbie friendliness 78/100
getsentry/sentry-cocoa#9219 · 1 comment ·
Maintainers usually reply within 1 day
-
feature-request
Difficulty 2/5 1-3 hours Newbie friendliness 74/100
DataDog/dd-sdk-ios#3255 · 1 comment ·
Maintainers usually reply within 3 days
-
bug good first issue
Difficulty 2/5 1-3 hours Newbie friendliness 90/100
repowise-dev/repowise#2785 ·
Maintainers usually reply within 1 day