Skip to content

fix(ENG-10262): fixed login url encoding#886

Merged
nsemets merged 2 commits intoCenterForOpenScience:feature/osf4i-in-progress-ssofrom
ihorsokhanexoft:fix/ENG-10262-2
Feb 18, 2026
Merged

fix(ENG-10262): fixed login url encoding#886
nsemets merged 2 commits intoCenterForOpenScience:feature/osf4i-in-progress-ssofrom
ihorsokhanexoft:fix/ENG-10262-2

Conversation

@ihorsokhanexoft
Copy link

https://openscience.atlassian.net/browse/ENG-10262

Purpose

For LOCAL env only:

A new next query parameter must be the first one to be encrypted and then encrypted one more time with service query parameter together.
So everything after localhost:8080/login?service= is encrypted and the next query param with its value is encrypted twice.

Also in the middle of the url, we should use ? instead of & (%3F - encoded, between login and next words) so that the next parameter belongs to service, not the main request

http://192.168.168.167:8080/login?service=http%3A%2F%2Flocalhost%3A5000%2Flogin%3Fnext%3Dhttp%253A%252F%252Flocalhost%253A4200%252F

And CAS should handle login, not angular, so we replace 4200 port in service query parameter by 5000

Copy link
Contributor

@Ostap-Zherebetskyi Ostap-Zherebetskyi left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM 🌟

@nsemets nsemets merged commit f3707fa into CenterForOpenScience:feature/osf4i-in-progress-sso Feb 18, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

Comments