Skip to content

PKCE flow issue with other than supabase code query in URL #911

Open
@vachmara

Description

@vachmara

Bug report

  • I confirm this is a bug with Supabase, not with my own application.
  • I confirm I have searched the Docs, GitHub Discussions, and Discord.

Describe the bug

I am using the @nuxtjs/supabase package and I encounter a bug described in this issue.

I am not able to use other PKCE flows because each time the third app redirects to my main app, GoTrueClient tries to refresh the session with the incorrect code parameter in the URL despite using detectSessionInUrl at initialization of GoTruClient.

I believe this function _isPKCEFlow should only watch specific URLs to manage other PKCE flows.

To Reproduce

  1. Setup a project with nuxt/supabase.
  2. Build a simple authentification system.
  3. On any page, use a query parameter ?code=random.

Expected behavior

Automatically, the GoTrueClient will try to set up a session at initialization and logout current user which is problematic.

Screenshots

image

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions