authgear / authgear/authgear-server
Reconsider necessity of having public origin redirects in POST apis
Open
- Dominant language
- Go
- Stars
- 2k
- Forks
- 125
- Avg merge
- 2d 17h
- Merged PRs (30d)
- 32
Description
Some http clients, such as [https://api.flutter.dev/flutter/dart-io/HttpClientRequest/followRedirects.html]()
Will not follow redirects on POST requests.
Therefore returning 308 in POST apis may cause problems. If it is not necessary, lets remove it.
Contributor guide
Research direction
Trace the public-origin redirect handling used by POST APIs and inspect how 308 responses are covered. Verify whether those redirects are required for the API flow; done means reaching an evidence-backed decision and updating the affected behavior and tests if removal is approved.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- go
- Domain
- api, backend
- Issue type
- Refactor
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 25/100