-
Notifications
You must be signed in to change notification settings - Fork 1.5k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Always getting skip as false in the consent request for android custom scheme redirect urls #2585
Comments
This is unfortunately expected behaviour as required by the OpenID Connect Certification process. Without it, OpenID Certification would not be achieved. The specification explains that public clients using a non-https redirect scheme have to go through consent always. Would you maybe be open to add this to the documentation to help others avoid going down this rabbit hole? :) https://github.com/ory/hydra/blob/master/docs/docs/guides/oauth2-public-spa-mobile.mdx |
What would be the consequences if just comment out that part of the code in ory hydra as shown in the image? |
Ok, I'll update the docs. |
I think a section explaining that public clients can’t skip consent (and the reason why) would be a perfect start :) |
@aeneasr Should I try adding a few lines about this at the end of https://github.com/ory/hydra/blob/master/docs/docs/guides/oauth2-public-spa-mobile.mdx as a part of |
Please do :) Sorry, we sometimes miss notifications |
No worries! I am working on the PR. |
Describe the bug
I am using the android-auth-package with a public client to initial auth-flow with PKCE.
I have successfully integrated the app & I am able to get refresh, id, access token.
But every time it I get skip = false even though I have set remember to true while accepting the initial consent,
data:image/s3,"s3://crabby-images/b7880/b78800d7c1770bf6ee4cd4e73e17b0c6b27c8f7f" alt="image"
After debugging the ory code, I believe this part is the issue
I am using custom scheme redirect URLs (e.g ->
com.example.com
) because of that the above-mentioned code triggers & I don't get skip = trueIf i use https based redirect URLs instead of custom scheme based URLs every thing works perfectly.
I think these are some related issues
#866
#2108
Reproducing the bug
Steps to reproduce the behavior:
Server logs
Server configuration
Expected behavior
Ory should set skip = true for android custom scheme redirect urls
A clear and concise description of what you expected to happen.
Environment
Additional context
Add any other context about the problem here.
The text was updated successfully, but these errors were encountered: