Settings flow does not respect the return_to with a `/settings` path
还没有人认领这个 Issue。
评估
- 难度
- 4/5
- 预计耗时
- 3-5 天
- 新手友好度
- 35/100
- Issue 类型
- 缺陷
- 描述清晰度
- 基本清楚
- 活跃度
- 停滞
调研方向
未指定文件、测试或入口点。使用自定义域名、相对的设置 UI 路径,以及指向包含 /settings 的 URL 的 return_to,重现设置流程;跟踪设置提交如何处理该值。完成的标准是提交后重定向到提供的 return_to URL,而不是停留在设置页面上。
由索引模型根据 Issue 内容生成。
描述
Preflight checklist
- I could not find a solution in the existing issues, docs, nor discussions.
- I agree to follow this project's Code of Conduct.
- I have read and am following this repository's Contribution Guidelines.
- This issue affects my Ory Network project.
- I have joined the Ory Community Slack.
- I am signed up to the Ory Security Patch Newsletter.
Describe the bug
A settings flow containing a return_to with the /settings path causes return_to to be ignored in the settings submit flow. An example is when you have an application with the url https://app.example.com/settings the URL will look like so:
https://auth.example.com/sefl-service/settings/browser?return_to=https://app.example.com/settings.
The project config has the following:
Custom Domain: auth.example.com
Custom UI: ui.example.com
Settings URL: /settings
note: this only happens with Custom domains and not when developing locally through the Ory tunnel
Reproducing the bug
- Create a project
- Add custom domain
- Add your custom UI base URL
- Keep the settings UI as a relative path
/settings - Initiate a
settingsflow with the return_to query parameter set to a route containing/settingsin the path (https://app.example.com/settings) - Submit the settings flow and see it stay on the settings page.
Relevant log output
No response
Relevant configuration
No response
Version
latest
On which operating system are you observing this issue?
None
In which environment are you deploying?
None
Additional Context
No response
- 主要语言
- Shell
- 星标
- 96
- 派生
- 8
- PR 合并指标
- 30 天内没有已合并 PR
环境准备
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
ory/network 的其他 Issue
-
bug
难度 4/5 3-5 天 新手友好度 38/100
-
Updating native registration flow with OIDC ID token for existing identity returns breaking response未关闭bug
难度 4/5 3-5 天 新手友好度 35/100
-
feat
难度 5/5 一周以上 新手友好度 25/100
-
bug
难度 4/5 3-5 天 新手友好度 30/100
-
feat
难度 5/5 一周以上 新手友好度 35/100
相似的 Issue
-
难度 2/5 1-3 小时 新手友好度 78/100
YosysHQ/oss-cad-suite-build#216 ·
-
难度 2/5 1-3 小时 新手友好度 84/100
ekalinin/github-markdown-toc#167 ·
-
out-of-date
难度 1/5 1 小时以内 新手友好度 82/100
CachyOS/CachyOS-PKGBUILDS#1917 ·
维护者通常 1 天内回复
-
package-update
难度 2/5 1-3 小时 新手友好度 78/100
-
bug needs triage
难度 2/5 1-3 小时 新手友好度 78/100
维护者通常 1 天内回复