Conversation
…ery (RFC 6749 3.1)
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
|
This PR has been closed automatically. This repo only keeps pull requests open when they come from a maintainer, or from a contributor a maintainer has assigned to the linked issue, and you aren't currently assigned to #3505. If a maintainer assigns you to #3505, this PR reopens on its own and there's nothing more you need to do here. Assignment is a maintainer call based on capacity; comments that only ask to be assigned don't factor in. What does help is engaging on the issue itself by confirming the repro, explaining why it matters for your use case, or describing the approach you'd take. You're welcome to keep pushing commits here (just avoid force-pushing, since GitHub can't reopen a rewritten branch), but that on its own won't get the PR reviewed or the issue assigned, and realistically most auto-closed PRs stay closed. There's no need to open a new PR either way. CONTRIBUTING.md has the full reasoning, but in short:
Maintainers: reopen, remove |
Problem
OAuthClientProvider._perform_authorization builds the redirect by appending a query string with a hardcoded question mark. When the advertised authorization_endpoint already carries a query (allowed by RFC 6749 section 3.1, e.g. Azure AD B2C policy param or multi-tenant tag), the result has a second question mark and the server misparses every authorization. The TS SDK is unaffected (URL + searchParams merge).
Solution
Merge via urlsplit/parse_qsl/urlunsplit so existing query params are retained and new params appended with ampersand. Plain endpoints render byte-identically to before.
Impact
OAuth flows against servers advertising query-bearing authorization endpoints now succeed; all other endpoints unchanged.
Evidence
Stdlib check: query-bearing endpoint merges correctly PASS; plain endpoint unchanged PASS. py_compile OK.
Fixes #3505