Skip to content

verify oauth authorize flow resumes correctly through signup #105

Description

@jaspermayone

Why

hackclub/auth#49 is a tagged showstopper for them: a user who lands on /oauth/authorize unauthenticated, signs UP (not in), never gets redirected back — the OAuth flow dies and the client app gets nothing. Weave's custom oauth login redirect flow (auth#oauth_login) may have the same hole for the signup path.

What

  • System test: start an authorization-code+PKCE flow logged out → choose signup → confirm email → assert the flow resumes at the consent screen and completes with a valid code delivered to the redirect_uri.
  • Same assertion through the magic-link login path, and through email confirmation happening in a DIFFERENT browser tab/session than the one holding the pending authorize request (the realistic failure mode).
  • Fix whatever return_to/state plumbing drops out.

Reference

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions