Why
hackclub/auth#49 is a tagged showstopper for them: a user who lands on /oauth/authorize unauthenticated, signs UP (not in), never gets redirected back — the OAuth flow dies and the client app gets nothing. Weave's custom oauth login redirect flow (auth#oauth_login) may have the same hole for the signup path.
What
- System test: start an authorization-code+PKCE flow logged out → choose signup → confirm email → assert the flow resumes at the consent screen and completes with a valid code delivered to the redirect_uri.
- Same assertion through the magic-link login path, and through email confirmation happening in a DIFFERENT browser tab/session than the one holding the pending authorize request (the realistic failure mode).
- Fix whatever return_to/state plumbing drops out.
Reference
Why
hackclub/auth#49 is a tagged showstopper for them: a user who lands on
/oauth/authorizeunauthenticated, signs UP (not in), never gets redirected back — the OAuth flow dies and the client app gets nothing. Weave's custom oauth login redirect flow (auth#oauth_login) may have the same hole for the signup path.What
Reference