IIdentityServerInteractionService.GetAuthorizationContextAsync regression in 7.4.0 #466
-
|
We are using the In our OpenID client (Expo AuthSession) we list multiple scopes, e.g: These are serialized into the returnUrl as: Historically (up to 7.3.x), IdentityServer accepted This appears to be a regression introduced in: DuendeSoftware/products#2096. Previously, My question is:
If this is intentional, we will raise the issue with Expo. Otherwise, we believe this change breaks existing clients that rely on EDIT: Having reviewed the spec, it seems the
|
Beta Was this translation helpful? Give feedback.
Replies: 1 comment 2 replies
-
|
Hi, and thanks very much for your detailed bug report and analysis! You are correct, this is in fact a regression. The plus character is valid in these encodings, and it was not our intention to change behavior in this way. I am currently working on a fix. Look for IdentityServer 7.4.5 with this fixed in the next day or so. |
Beta Was this translation helpful? Give feedback.
@cri5ti we've just released IdentityServer 7.4.5, which should fix this issue.
Please give it a try and let us know how you get on!