Settings flow does not respect the return_to with a `/settings` path
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 4/5
- Thời gian dự kiến
- 3-5 ngày
- Mức phù hợp với người mới
- 35/100
- Loại issue
- Lỗi
- Độ rõ ràng
- Khá rõ ràng
- Mức độ hoạt động
- Đình trệ
- Lĩnh vực
- authentication
Hướng nghiên cứu
Không có tệp, bài kiểm thử hoặc điểm vào nào được nêu. Hãy tái hiện luồng cài đặt với một tên miền tùy chỉnh, một đường dẫn tương đối đến UI cài đặt và một return_to trỏ đến URL chứa /settings; theo dõi cách quá trình gửi cài đặt xử lý giá trị đó. Được xem là hoàn tất khi quá trình gửi chuyển hướng đến URL return_to được cung cấp thay vì ở lại trang cài đặt.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
Preflight checklist
- I could not find a solution in the existing issues, docs, nor discussions.
- I agree to follow this project's Code of Conduct.
- I have read and am following this repository's Contribution Guidelines.
- This issue affects my Ory Network project.
- I have joined the Ory Community Slack.
- I am signed up to the Ory Security Patch Newsletter.
Describe the bug
A settings flow containing a return_to with the /settings path causes return_to to be ignored in the settings submit flow. An example is when you have an application with the url https://app.example.com/settings the URL will look like so:
https://auth.example.com/sefl-service/settings/browser?return_to=https://app.example.com/settings.
The project config has the following:
Custom Domain: auth.example.com
Custom UI: ui.example.com
Settings URL: /settings
note: this only happens with Custom domains and not when developing locally through the Ory tunnel
Reproducing the bug
- Create a project
- Add custom domain
- Add your custom UI base URL
- Keep the settings UI as a relative path
/settings - Initiate a
settingsflow with the return_to query parameter set to a route containing/settingsin the path (https://app.example.com/settings) - Submit the settings flow and see it stay on the settings page.
Relevant log output
No response
Relevant configuration
No response
Version
latest
On which operating system are you observing this issue?
None
In which environment are you deploying?
None
Additional Context
No response
- Ngôn ngữ chính
- Shell
- Star
- 96
- Fork
- 8
- Chỉ số merge pull request
- Không có pull request nào được merge trong 30 ngày
Chuẩn bị môi trường
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của ory/network
-
bug
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 38/100
-
Updating native registration flow with OIDC ID token for existing identity returns breaking responseĐang mởbug
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 35/100
-
Ory Account Experience (hosted UI) registration trait setup via creation of registration flowĐang mởfeat
Độ khó 5/5 Hơn một tuần Mức phù hợp với người mới 25/100
-
selfservice.flows.login.style reverts to identifier_first despite explicitly setting passwordĐang mởbug
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 30/100
-
feat
Độ khó 5/5 Hơn một tuần Mức phù hợp với người mới 35/100
Issue tương tự
-
🎙️ task - fix(deployer): deploy --env prep runs deploy:dev where the repo declares deploy:prepĐang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 88/100
-
backlog bug
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 86/100
WLAN-Pi/wlanpi-profiler#306 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
area: backend good first issue priority: P3 - low size: S type: bug
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
Mizithra/ActiveTerrain#31 ·
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 68/100
obra/superpowers#2422 ·
Maintainer thường phản hồi trong vòng 6 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 88/100
ComplianceAsCode/content#15152 ·
Maintainer thường phản hồi trong vòng 3 ngày