You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
feat(oauth2): support custom URI schemes for Native clients across redirect_uris, allowed_origins, post_logout_redirect_uris
Native (mobile/desktop) OAuth2 clients can now register custom app
schemes (myapp://callback) in allowed_origins and
post_logout_redirect_uris via the admin API and React UI, matching
the support redirect_uris already had. The OIDC end-session flow
honors a registered custom-scheme post-logout URI at runtime.
Security hardening (found via adversarial code review):
- Deny-list for dangerous/launch pseudo-schemes (javascript:, data:,
intent:, etc.) and plain http, centralized in HttpUtils and shared
by write-time validation (ClientService) and runtime allow-gates
(Client::isUriAllowed/isPostLogoutUriAllowed).
- RFC 8252 loopback carve-out: http://127.0.0.1|localhost redirect
URIs remain allowed for Native clients (the standard native-app
pattern), only non-loopback http is blocked.
- Cross-client custom-scheme uniqueness check extended to all three
URI fields (was redirect_uris only), preventing OS-level scheme
interception between clients.
- Defense-in-depth: runtime gates independently re-check the scheme
deny-list rather than relying solely on write-time validation.
- Fixed a pre-existing crash (missing array key "host") in
URLUtils::canonicalUrl/Client::isPostLogoutUriAllowed for host-less
custom-scheme URIs (mailto:, file:///x).
- Fixed a pre-existing substring false-positive in the cross-client
scheme collision check (e.g. "roipapp" matching inside
"androipapp://...").
Also fixes an unrelated pre-existing bug in UserLoginTurnstileTest
where assigning null (from an unset env var) to a typed string
property threw a TypeError before the intended skip-guard could run.
Plan: docs/plans/2026-07-14-native-clients-custom-schemes.md
0 commit comments