Skip to content

Frontend SDK changes OAuth authorization parameters containing URL characters #7642

Description

@dakjdakd

The frontend SDK lets callers pass authorization_params when opening an OAuth connection. These values need to reach Nango exactly as supplied because providers use them for consent, account selection, and other authorization options. A previous fix in #4288 encoded connectionConfig.params, but authorization_params still append their names and values to the connection URL without encoding them.

For example, a value of consent&scope=read becomes authorization_params[prompt]=consent&scope=read in the URL. The browser parses scope=read as a separate query parameter, so Nango receives a different authorization request. A # in a value also cuts off the remaining query string.

The SDK should URL-encode each authorization parameter name and value while preserving the authorization_params[...] query shape expected by the server. Values containing &, +, #, or other reserved characters should survive the connection flow unchanged. A frontend SDK regression test with reserved characters would cover this path.

No activity

Activity on this issue will appear here.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions