Skip to content
This repository has been archived by the owner on Dec 22, 2023. It is now read-only.

Ignore query and fragment in validating allowed callback URLs #1211

Closed
louischan-oursky opened this issue Feb 13, 2020 · 0 comments · Fixed by #1212
Closed

Ignore query and fragment in validating allowed callback URLs #1211

louischan-oursky opened this issue Feb 13, 2020 · 0 comments · Fixed by #1212
Assignees

Comments

@louischan-oursky
Copy link
Contributor

The validation is doing exact string match. It is more useful if the provided callback URL is first with its query and fragment removed.

For example if http://localhost:3001/auth is allowed then the callback URL http://localhost:3001/auth?a=b should be allowed.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

Successfully merging a pull request may close this issue.

1 participant