OpenConext / OpenConext/OpenConext-access

Plaintext redirect on login

Open
#946 0 comments 0 reactions 1 assignee View on GitHub

@oharsta is already working on this.

Since Sep 10, 2026.

Dominant language
JavaScript
Stars
4
Forks
0
Avg merge
1d 14h
Merged PRs (30d)
22

Description

When loging in on SURF Access (both Institution and Commercial organisation) the browser is redirected to the plaintext version of oauth2/authorization/oidcng after which the browser is sent to the https version of the same endpoint:

Request URL
https://test2.surfaccess.nl/api/v1/users/login?force=true
Request Method GET

Request URL
http://test2.surfaccess.nl/oauth2/authorization/oidcng
Request Method GET

Request URL
https://test2.surfaccess.nl/oauth2/authorization/oidcng
Request Method GET

Request URL
https://connect.test2.surfconext.nl/oidc/authorize?...
Request Method GET

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.