mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
refactor: simplify OAuth2 authorization flow and use 302 redirects (#18923)
# Refactor OAuth2 Provider Authorization Flow This PR refactors the OAuth2 provider authorization flow by: 1. Removing the `authorizeMW` middleware and directly implementing its functionality in the `ShowAuthorizePage` handler 2. Simplifying function signatures by removing unnecessary parameters: - Removed `db` parameter from `ShowAuthorizePage` - Removed `accessURL` parameter from `ProcessAuthorize` 3. Changing the redirect status code in `ProcessAuthorize` from 307 (Temporary Redirect) to 302 (Found) to improve compatibility with external OAuth2 apps and browsers. (Technical explanation: we replied with a 307 to a POST request, thus the browser performs a redirect to that URL as a POST request, but we need it to be a GET request to be compatible. Thus, we use the 302 redirect so that browsers turn it into a GET request when redirecting back to the redirect_uri.) The changes maintain the same functionality while simplifying the code and improving compatibility with external systems.
This commit is contained in:
+2
-2
@@ -116,7 +116,7 @@ func (api *API) deleteOAuth2ProviderAppSecret() http.HandlerFunc {
|
||||
// @Success 200 "Returns HTML authorization page"
|
||||
// @Router /oauth2/authorize [get]
|
||||
func (api *API) getOAuth2ProviderAppAuthorize() http.HandlerFunc {
|
||||
return oauth2provider.ShowAuthorizePage(api.Database, api.AccessURL)
|
||||
return oauth2provider.ShowAuthorizePage(api.AccessURL)
|
||||
}
|
||||
|
||||
// @Summary OAuth2 authorization request (POST - process authorization).
|
||||
@@ -131,7 +131,7 @@ func (api *API) getOAuth2ProviderAppAuthorize() http.HandlerFunc {
|
||||
// @Success 302 "Returns redirect with authorization code"
|
||||
// @Router /oauth2/authorize [post]
|
||||
func (api *API) postOAuth2ProviderAppAuthorize() http.HandlerFunc {
|
||||
return oauth2provider.ProcessAuthorize(api.Database, api.AccessURL)
|
||||
return oauth2provider.ProcessAuthorize(api.Database)
|
||||
}
|
||||
|
||||
// @Summary OAuth2 token exchange.
|
||||
|
||||
Reference in New Issue
Block a user