Closed balazsorban44 closed 2 weeks ago
The latest updates on your projects. Learn more about Vercel for Git ↗︎
Name | Status | Preview | Comments | Updated (UTC) |
---|---|---|---|---|
auth-docs | ✅ Ready (Inspect) | Visit Preview | 💬 Add feedback | Apr 29, 2024 7:55pm |
Attention: Patch coverage is 30.76923%
with 9 lines
in your changes are missing coverage. Please review.
Project coverage is 41.46%. Comparing base (
f762906
) to head (7f4c6ed
).
Files | Patch % | Lines |
---|---|---|
...es/core/src/lib/actions/callback/oauth/callback.ts | 33.33% | 8 Missing :warning: |
packages/core/src/providers/linkedin.ts | 0.00% | 1 Missing :warning: |
:umbrella: View full report in Codecov by Sentry.
:loudspeaker: Have feedback on the report? Share it here.
Fixes #8831
Some providers choke when there is a
code_verifier
param on a request that they cannot handle (like LinkedIn not supporting PKCE), even if this is not according to the spec.Per spec:
https://datatracker.ietf.org/doc/html/rfc6749#section-3.2
https://datatracker.ietf.org/doc/html/rfc7636#section-7.2
This PR strips the unwanted param if the provider is configured without
checks: ["pkce"]