Skip to content

feat(auth): end popup OAuth logins on a self-closing page with disableRedirect - #441

Merged
themaherkhalil merged 1 commit into
devfrom
feat/oauth-popup-disable-redirect
Oct 3, 2026
Merged

themaherkhalil merged 1 commit into
devfrom
feat/oauth-popup-disable-redirect

Conversation

@themaherkhalil

Copy link
Copy Markdown
Collaborator
  • An OAuth login started with ?disableRedirect=true keeps the flag in the session across the provider round trip and ends on a small page that closes its window, instead of redirecting the popup to the configured app; every other login redirects as before
  • The page sends its own Content-Security-Policy, with a one-time nonce for its script

…eRedirect

- An OAuth login started with ?disableRedirect=true keeps the flag in the session across the
  provider round trip and ends on a small page that closes its window, instead of redirecting
  the popup to the configured app; every other login redirects as before
- The page sends its own Content-Security-Policy, with a one-time nonce for its script
@themaherkhalil
themaherkhalil requested a review from a team as a code owner October 3, 2026 13:18
@snyk-io

snyk-io Bot commented Oct 3, 2026

Copy link
Copy Markdown

✅ Snyk checks have passed. No issues have been found so far.

Status Scan Engine Critical High Medium Low Total (0)
✅ Open Source Security 0 0 0 0 0 issues

💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse.

@themaherkhalil
themaherkhalil merged commit 88ec92a into dev Oct 3, 2026
6 checks passed
@themaherkhalil
themaherkhalil deleted the feat/oauth-popup-disable-redirect branch October 3, 2026 13:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant