nextcloud / nextcloud/server

[Bug]: Adding a query to login/v2/flow results in a wrong redirect for clients

Open
#59,874 7 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

0. Needs triage 32-feedback bug team: IDP
Dominant language
PHP
Stars
36.9k
Forks
5.2k
Avg merge
2d 3h
Merged PRs (30d)
713

Description

⚠️ This issue respects the following points: ⚠️
Bug description
https://somenextcloudinstance.com/login/v2/flow/ZD1vrsN3Ed4aTOUyJ68GlZkOSTt4UBTeJKgSCbdNM3O3Qtta2Lvar6MUDjTDG29RfbuEMs1SmAYa8n45eZRJA5dUVoZGGb?user=some.name@somenextcloudinstance.com

Having user as a query in the URL does not do proper redirecting on clients.
Instead of redirecting to the "grant access" screen, it redirects to the Nextcloud home page.
This means we cannot log in to clients.

Steps to reproduce
  1. Open a client.
  2. Use "import account" or use QR code to log in, to where the email will be auto filled.
  3. Observe
Expected behavior

It should lead to "grant access" page so clients can finalize logging in.

Nextcloud Server version

32

Operating system

None

PHP engine version

None

Web server

None

Database engine version

None

Is this bug present after an update or on a fresh install?

None

Are you using the Nextcloud Server Encryption module?

None

What user-backends are you using?
  • Default user-backend (database)
  • LDAP/ Active Directory
  • SSO - SAML
  • Other
Configuration report

List of activated Apps

Nextcloud Signing status

Nextcloud Logs

Additional info

No response

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by reproducing the login/v2/flow request with the user query shown in the issue and trace the endpoint's redirect handling. Compare the result with a request without the query; done means client login reaches the grant access page and the import or QR-code flow can finish.

Written by the indexing model from the issue text.

Assessment

Tech stack
php
Domain
api, authentication
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Quiet
Clarity
Needs clarification
Newbie friendliness
48/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.