Skip to content

fix(verify): preserve custom scheme in PKCE redirects - #2865

Open
Tyagiquamar wants to merge 1 commit into
supabase:masterfrom
Tyagiquamar:fix/pkce-custom-scheme-redirect-2423
Open

Tyagiquamar wants to merge 1 commit into
supabase:masterfrom
Tyagiquamar:fix/pkce-custom-scheme-redirect-2423

Conversation

@Tyagiquamar

Copy link
Copy Markdown

Summary

  • Preserve bare custom-scheme redirect URIs (for example myapp://) when appending the PKCE auth code query parameter.
  • Avoids Go url.URL re-serialization dropping the // authority marker, which corrupted auth codes on iOS native clients.

Test plan

  • docker run --rm -v D:/pers/open source/supabase-auth:/work -w /work golang:1.27-bookworm go test ./internal/api/ -run TestPrepPKCERedirectURLCustomScheme -count=1 (exit 0, ok in 0.280s after compile)
  • docker run ... gofmt -l internal/api/verify.go internal/api/verify_test.go (no output, exit 0)

Fixes #2423

Avoid re-serializing bare custom-scheme redirect URIs through url.URL,
which drops the authority marker and corrupts PKCE auth codes on iOS.

Fixes supabase#2423
@Tyagiquamar
Tyagiquamar requested a review from a team as a code owner October 10, 2026 17:54

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

prepPKCERedirectURLdrops // from custom scheme URIs, corrupting PKCE auth code on iOS (%23)

1 participant