Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

please remove cpTrigger as a segment from redirectUri #33

Open
bencresty opened this issue Jul 16, 2021 · 0 comments
Open

please remove cpTrigger as a segment from redirectUri #33

bencresty opened this issue Jul 16, 2021 · 0 comments

Comments

@bencresty
Copy link

bencresty commented Jul 16, 2021

First of all, thanks for this plugin! Seems to work great!

When setting a custom cpTrigger in general.php we do that to hide our url for the control panel on purpose. So it's not great to have this cp trigger used as an url segment on the redirectUri of the oAuth apps.

I searched for a setting in the plugin to change this behaviour, but couldn't find one.

Please remove the cpTrigger as a segment from the redirectUri. Just domain/oath/... should be sufficient I'd say. But correct me if I'm wong. That way we don't expose the url to the cp inlog (even when it's only used in the back channel).

Thanks!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant