The frontend SDK lets callers pass authorization_params when opening an OAuth connection. These values need to reach Nango exactly as supplied because providers use them for consent, account selection, and other authorization options. A previous fix in #4288 encoded connectionConfig.params, but authorization_params still append their names and values to the connection URL without encoding them.
For example, a value of consent&scope=read becomes authorization_params[prompt]=consent&scope=read in the URL. The browser parses scope=read as a separate query parameter, so Nango receives a different authorization request. A # in a value also cuts off the remaining query string.
The SDK should URL-encode each authorization parameter name and value while preserving the authorization_params[...] query shape expected by the server. Values containing &, +, #, or other reserved characters should survive the connection flow unchanged. A frontend SDK regression test with reserved characters would cover this path.
The frontend SDK lets callers pass
authorization_paramswhen opening an OAuth connection. These values need to reach Nango exactly as supplied because providers use them for consent, account selection, and other authorization options. A previous fix in #4288 encodedconnectionConfig.params, butauthorization_paramsstill append their names and values to the connection URL without encoding them.For example, a value of
consent&scope=readbecomesauthorization_params[prompt]=consent&scope=readin the URL. The browser parsesscope=readas a separate query parameter, so Nango receives a different authorization request. A#in a value also cuts off the remaining query string.The SDK should URL-encode each authorization parameter name and value while preserving the
authorization_params[...]query shape expected by the server. Values containing&,+,#, or other reserved characters should survive the connection flow unchanged. A frontend SDK regression test with reserved characters would cover this path.