feat: Normalize redirection URLs and globs - #535

Merged
kangmingtay merged 1 commit into
masterfrom
hf/normalize-redirect-uris
Jul 26, 2022
Merged

feat: Normalize redirection URLs and globs#535
kangmingtay merged 1 commit into
masterfrom
hf/normalize-redirect-uris

Conversation

@hf

@hfhf commented Jul 13, 2022

Copy link
Copy Markdown
Contributor

What kind of change does this PR introduce?

If a user specifies a redirect URL glob of the form:

https://example.com

But they send a redirect_to parameter to /authorize of the form:

https://example.com/

(Note the trailing slash!)

GoTrue will not match the two URLs, even though in the modern web they are equivalent. This PR normalizes HTTP(S) URLs to remove the trailing slash in the redirect_to parameter; as well as ignoring any trailing slashes in the URL allow list.

@hf
hfforce-pushed the hf/normalize-redirect-uris branch from 236f9c4 to 8097a73CompareJuly 13, 2022 09:43

@kangmingtaykangmingtay left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

looks good! but can we also add a test case for this?

Comment threadapi/helpers.go
@hf

hf commented Jul 14, 2022

Copy link
Copy Markdown
ContributorAuthor

looks good! but can we also add a test case for this

Yeah I've been trying to find a way to test it but it's a bit too complex of a case, and the methods have to become public otherwise, so I'm not sure if it's worth it.

@kangmingtay

Copy link
Copy Markdown
Member

@hf you can consider adding it as a test case here

@hf

hf commented Jul 15, 2022

Copy link
Copy Markdown
ContributorAuthor

@hf you can consider adding it as a test case here

Oh that's splendid!

@hf
hfforce-pushed the hf/normalize-redirect-uris branch 3 times, most recently from 2675dd1 to 613ae16CompareJuly 15, 2022 08:41
@hf
hf requested a review from kangmingtayJuly 15, 2022 08:41
@hf
hfforce-pushed the hf/normalize-redirect-uris branch 4 times, most recently from 23d8e11 to a8b78fdCompareJuly 15, 2022 13:55
@hf

hf commented Jul 15, 2022

Copy link
Copy Markdown
ContributorAuthor

@kangmingtay Moving the parsing logic to the configuration doesn't really help much and just duplicates code. I also think it breaks some non-compliant tests as the code has to panic.

Otherwise, I think it's good this way -- the tests are failing because of a rate limit check. I'm trying to find a way to remove it on these tests. Please review again when you can.

@J0

J0 commented Jul 15, 2022

Copy link
Copy Markdown
Contributor

Hmm throwing out ideas here: off the top of head I can think of three suggestions to deal with the rate limiting.

  1. Use build tags for tests

  2. Establish a naming convention for tests with rate limits and then filter tests via regexp like go test -p 1 -v -run '<relevant regexp>'

  3. Gate the rate limiting at api.go with an env var so that it's only enabled when an env var is set to true

    \3. is a little clunky but 1 and 2 would constrain the separation to only tests. Imagine there would be other cases outside of testing (e.g. benchmarks) where we want to turn off rate limiting. If any of the three would be potential solutions lmk and I can file a PR on Sunday or so

Let me know if there are further suggestions or other options we should consider!

Let me also look into our rate limiter lib to see if there's something built in we can use

@kangmingtay

Copy link
Copy Markdown
Member

Moving the parsing logic to the configuration doesn't really help much and just duplicates code.

@hf why can't we just move the parsing logic to the configuration completely so we do it once when the config is loaded? i don't see why it would be duplicated?

@hf
hfforce-pushed the hf/normalize-redirect-uris branch 2 times, most recently from c6b3ab4 to e2f99caCompareJuly 26, 2022 07:38
@hf
hfforce-pushed the hf/normalize-redirect-uris branch from e2f99ca to c6e3938CompareJuly 26, 2022 08:01
@kangmingtay
kangmingtay merged commit d6f4a2a into masterJul 26, 2022
@kangmingtay
kangmingtay deleted the hf/normalize-redirect-uris branch July 26, 2022 08:11
@github-actions

Copy link
Copy Markdown
Contributor

🎉 This PR is included in version 2.10.0 🎉

The release is available on GitHub release

Your semantic-release bot 📦🚀

hf added a commit that referenced this pull request Aug 4, 2022
hf added a commit that referenced this pull request Aug 4, 2022
* fix: Revert "fix: don't normalise mobile deeplinks (#591)"
This reverts commit 4042c80.
* fix: Revert "feat: Normalize redirection URLs and globs (#535)"
This reverts commit d6f4a2a.
uxodb pushed a commit to uxodb/auth that referenced this pull request Nov 13, 2024
Co-authored-by: Stojan Dimitrovski <--local>
uxodb pushed a commit to uxodb/auth that referenced this pull request Nov 13, 2024
)
* fix: Revert "fix: don't normalise mobile deeplinks (supabase#591)"
This reverts commit 4042c80.
* fix: Revert "feat: Normalize redirection URLs and globs (supabase#535)"
This reverts commit d6f4a2a.
LashaJini pushed a commit to LashaJini/auth that referenced this pull request Nov 13, 2024
Co-authored-by: Stojan Dimitrovski <--local>
LashaJini pushed a commit to LashaJini/auth that referenced this pull request Nov 13, 2024
)
* fix: Revert "fix: don't normalise mobile deeplinks (supabase#591)"
This reverts commit 4042c80.
* fix: Revert "feat: Normalize redirection URLs and globs (supabase#535)"
This reverts commit d6f4a2a.
LashaJini pushed a commit to LashaJini/auth that referenced this pull request Nov 15, 2024
Co-authored-by: Stojan Dimitrovski <--local>
LashaJini pushed a commit to LashaJini/auth that referenced this pull request Nov 15, 2024
)
* fix: Revert "fix: don't normalise mobile deeplinks (supabase#591)"
This reverts commit 4042c80.
* fix: Revert "feat: Normalize redirection URLs and globs (supabase#535)"
This reverts commit d6f4a2a.
cemalkilic pushed a commit that referenced this pull request Aug 7, 2025
Co-authored-by: Stojan Dimitrovski <--local>
cemalkilic pushed a commit that referenced this pull request Aug 7, 2025
* fix: Revert "fix: don't normalise mobile deeplinks (#591)"
This reverts commit 4042c80.
* fix: Revert "feat: Normalize redirection URLs and globs (#535)"
This reverts commit d6f4a2a.
xeladotbe pushed a commit to xeladotbe/supabase-auth that referenced this pull request Sep 27, 2025
Co-authored-by: Stojan Dimitrovski <--local>
xeladotbe pushed a commit to xeladotbe/supabase-auth that referenced this pull request Sep 27, 2025
)
* fix: Revert "fix: don't normalise mobile deeplinks (supabase#591)"
This reverts commit 4042c80.
* fix: Revert "feat: Normalize redirection URLs and globs (supabase#535)"
This reverts commit d6f4a2a.
fadymak pushed a commit that referenced this pull request Sep 30, 2025
Co-authored-by: Stojan Dimitrovski <--local>
fadymak pushed a commit that referenced this pull request Sep 30, 2025
* fix: Revert "fix: don't normalise mobile deeplinks (#591)"
This reverts commit 4042c80.
* fix: Revert "feat: Normalize redirection URLs and globs (#535)"
This reverts commit d6f4a2a.
@coderabbitaicoderabbitaiBot mentioned this pull request Apr 20, 2026
7 tasks
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@hf@kangmingtay@J0
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

feat: Normalize redirection URLs and globs - #535

Merged
kangmingtay merged 1 commit into
masterfrom
hf/normalize-redirect-uris
Jul 26, 2022
Merged

feat: Normalize redirection URLs and globs#535
kangmingtay merged 1 commit into
masterfrom
hf/normalize-redirect-uris

Conversation

@hf

@hfhf commented Jul 13, 2022

Copy link
Copy Markdown
Contributor

What kind of change does this PR introduce?

If a user specifies a redirect URL glob of the form:

https://example.com

But they send a redirect_to parameter to /authorize of the form:

https://example.com/

(Note the trailing slash!)

GoTrue will not match the two URLs, even though in the modern web they are equivalent. This PR normalizes HTTP(S) URLs to remove the trailing slash in the redirect_to parameter; as well as ignoring any trailing slashes in the URL allow list.

@hf
hfforce-pushed the hf/normalize-redirect-uris branch from 236f9c4 to 8097a73CompareJuly 13, 2022 09:43

@kangmingtaykangmingtay left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

looks good! but can we also add a test case for this?

Comment threadapi/helpers.go
@hf

hf commented Jul 14, 2022

Copy link
Copy Markdown
ContributorAuthor

looks good! but can we also add a test case for this

Yeah I've been trying to find a way to test it but it's a bit too complex of a case, and the methods have to become public otherwise, so I'm not sure if it's worth it.

@kangmingtay

Copy link
Copy Markdown
Member

@hf you can consider adding it as a test case here

@hf

hf commented Jul 15, 2022

Copy link
Copy Markdown
ContributorAuthor

@hf you can consider adding it as a test case here

Oh that's splendid!

@hf
hfforce-pushed the hf/normalize-redirect-uris branch 3 times, most recently from 2675dd1 to 613ae16CompareJuly 15, 2022 08:41
@hf
hf requested a review from kangmingtayJuly 15, 2022 08:41
@hf
hfforce-pushed the hf/normalize-redirect-uris branch 4 times, most recently from 23d8e11 to a8b78fdCompareJuly 15, 2022 13:55
@hf

hf commented Jul 15, 2022

Copy link
Copy Markdown
ContributorAuthor

@kangmingtay Moving the parsing logic to the configuration doesn't really help much and just duplicates code. I also think it breaks some non-compliant tests as the code has to panic.

Otherwise, I think it's good this way -- the tests are failing because of a rate limit check. I'm trying to find a way to remove it on these tests. Please review again when you can.

@J0

J0 commented Jul 15, 2022

Copy link
Copy Markdown
Contributor

Hmm throwing out ideas here: off the top of head I can think of three suggestions to deal with the rate limiting.

  1. Use build tags for tests

  2. Establish a naming convention for tests with rate limits and then filter tests via regexp like go test -p 1 -v -run '<relevant regexp>'

  3. Gate the rate limiting at api.go with an env var so that it's only enabled when an env var is set to true

    \3. is a little clunky but 1 and 2 would constrain the separation to only tests. Imagine there would be other cases outside of testing (e.g. benchmarks) where we want to turn off rate limiting. If any of the three would be potential solutions lmk and I can file a PR on Sunday or so

Let me know if there are further suggestions or other options we should consider!

Let me also look into our rate limiter lib to see if there's something built in we can use

@kangmingtay

Copy link
Copy Markdown
Member

Moving the parsing logic to the configuration doesn't really help much and just duplicates code.

@hf why can't we just move the parsing logic to the configuration completely so we do it once when the config is loaded? i don't see why it would be duplicated?

@hf
hfforce-pushed the hf/normalize-redirect-uris branch 2 times, most recently from c6b3ab4 to e2f99caCompareJuly 26, 2022 07:38
@hf
hfforce-pushed the hf/normalize-redirect-uris branch from e2f99ca to c6e3938CompareJuly 26, 2022 08:01
@kangmingtay
kangmingtay merged commit d6f4a2a into masterJul 26, 2022
@kangmingtay
kangmingtay deleted the hf/normalize-redirect-uris branch July 26, 2022 08:11
@github-actions

Copy link
Copy Markdown
Contributor

🎉 This PR is included in version 2.10.0 🎉

The release is available on GitHub release

Your semantic-release bot 📦🚀

hf added a commit that referenced this pull request Aug 4, 2022
hf added a commit that referenced this pull request Aug 4, 2022
* fix: Revert "fix: don't normalise mobile deeplinks (#591)"
This reverts commit 4042c80.
* fix: Revert "feat: Normalize redirection URLs and globs (#535)"
This reverts commit d6f4a2a.
uxodb pushed a commit to uxodb/auth that referenced this pull request Nov 13, 2024
Co-authored-by: Stojan Dimitrovski <--local>
uxodb pushed a commit to uxodb/auth that referenced this pull request Nov 13, 2024
)
* fix: Revert "fix: don't normalise mobile deeplinks (supabase#591)"
This reverts commit 4042c80.
* fix: Revert "feat: Normalize redirection URLs and globs (supabase#535)"
This reverts commit d6f4a2a.
LashaJini pushed a commit to LashaJini/auth that referenced this pull request Nov 13, 2024
Co-authored-by: Stojan Dimitrovski <--local>
LashaJini pushed a commit to LashaJini/auth that referenced this pull request Nov 13, 2024
)
* fix: Revert "fix: don't normalise mobile deeplinks (supabase#591)"
This reverts commit 4042c80.
* fix: Revert "feat: Normalize redirection URLs and globs (supabase#535)"
This reverts commit d6f4a2a.
LashaJini pushed a commit to LashaJini/auth that referenced this pull request Nov 15, 2024
Co-authored-by: Stojan Dimitrovski <--local>
LashaJini pushed a commit to LashaJini/auth that referenced this pull request Nov 15, 2024
)
* fix: Revert "fix: don't normalise mobile deeplinks (supabase#591)"
This reverts commit 4042c80.
* fix: Revert "feat: Normalize redirection URLs and globs (supabase#535)"
This reverts commit d6f4a2a.
cemalkilic pushed a commit that referenced this pull request Aug 7, 2025
Co-authored-by: Stojan Dimitrovski <--local>
cemalkilic pushed a commit that referenced this pull request Aug 7, 2025
* fix: Revert "fix: don't normalise mobile deeplinks (#591)"
This reverts commit 4042c80.
* fix: Revert "feat: Normalize redirection URLs and globs (#535)"
This reverts commit d6f4a2a.
xeladotbe pushed a commit to xeladotbe/supabase-auth that referenced this pull request Sep 27, 2025
Co-authored-by: Stojan Dimitrovski <--local>
xeladotbe pushed a commit to xeladotbe/supabase-auth that referenced this pull request Sep 27, 2025
)
* fix: Revert "fix: don't normalise mobile deeplinks (supabase#591)"
This reverts commit 4042c80.
* fix: Revert "feat: Normalize redirection URLs and globs (supabase#535)"
This reverts commit d6f4a2a.
fadymak pushed a commit that referenced this pull request Sep 30, 2025
Co-authored-by: Stojan Dimitrovski <--local>
fadymak pushed a commit that referenced this pull request Sep 30, 2025
* fix: Revert "fix: don't normalise mobile deeplinks (#591)"
This reverts commit 4042c80.
* fix: Revert "feat: Normalize redirection URLs and globs (#535)"
This reverts commit d6f4a2a.
@coderabbitaicoderabbitaiBot mentioned this pull request Apr 20, 2026
7 tasks
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@hf@kangmingtay@J0
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat: Normalize redirection URLs and globs - #535

Merged
kangmingtay merged 1 commit into
masterfrom
hf/normalize-redirect-uris
Jul 26, 2022
Merged

feat: Normalize redirection URLs and globs#535
kangmingtay merged 1 commit into
masterfrom
hf/normalize-redirect-uris

Conversation

@hf

@hfhf commented Jul 13, 2022

Copy link
Copy Markdown
Contributor

What kind of change does this PR introduce?

If a user specifies a redirect URL glob of the form:

https://example.com

But they send a redirect_to parameter to /authorize of the form:

https://example.com/

(Note the trailing slash!)

GoTrue will not match the two URLs, even though in the modern web they are equivalent. This PR normalizes HTTP(S) URLs to remove the trailing slash in the redirect_to parameter; as well as ignoring any trailing slashes in the URL allow list.

@hf
hfforce-pushed the hf/normalize-redirect-uris branch from 236f9c4 to 8097a73CompareJuly 13, 2022 09:43

@kangmingtaykangmingtay left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

looks good! but can we also add a test case for this?

Comment threadapi/helpers.go
@hf

hf commented Jul 14, 2022

Copy link
Copy Markdown
ContributorAuthor

looks good! but can we also add a test case for this

Yeah I've been trying to find a way to test it but it's a bit too complex of a case, and the methods have to become public otherwise, so I'm not sure if it's worth it.

@kangmingtay

Copy link
Copy Markdown
Member

@hf you can consider adding it as a test case here

@hf

hf commented Jul 15, 2022

Copy link
Copy Markdown
ContributorAuthor

@hf you can consider adding it as a test case here

Oh that's splendid!

@hf
hfforce-pushed the hf/normalize-redirect-uris branch 3 times, most recently from 2675dd1 to 613ae16CompareJuly 15, 2022 08:41
@hf
hf requested a review from kangmingtayJuly 15, 2022 08:41
@hf
hfforce-pushed the hf/normalize-redirect-uris branch 4 times, most recently from 23d8e11 to a8b78fdCompareJuly 15, 2022 13:55
@hf

hf commented Jul 15, 2022

Copy link
Copy Markdown
ContributorAuthor

@kangmingtay Moving the parsing logic to the configuration doesn't really help much and just duplicates code. I also think it breaks some non-compliant tests as the code has to panic.

Otherwise, I think it's good this way -- the tests are failing because of a rate limit check. I'm trying to find a way to remove it on these tests. Please review again when you can.

@J0

J0 commented Jul 15, 2022

Copy link
Copy Markdown
Contributor

Hmm throwing out ideas here: off the top of head I can think of three suggestions to deal with the rate limiting.

  1. Use build tags for tests

  2. Establish a naming convention for tests with rate limits and then filter tests via regexp like go test -p 1 -v -run '<relevant regexp>'

  3. Gate the rate limiting at api.go with an env var so that it's only enabled when an env var is set to true

    \3. is a little clunky but 1 and 2 would constrain the separation to only tests. Imagine there would be other cases outside of testing (e.g. benchmarks) where we want to turn off rate limiting. If any of the three would be potential solutions lmk and I can file a PR on Sunday or so

Let me know if there are further suggestions or other options we should consider!

Let me also look into our rate limiter lib to see if there's something built in we can use

@kangmingtay

Copy link
Copy Markdown
Member

Moving the parsing logic to the configuration doesn't really help much and just duplicates code.

@hf why can't we just move the parsing logic to the configuration completely so we do it once when the config is loaded? i don't see why it would be duplicated?

@hf
hfforce-pushed the hf/normalize-redirect-uris branch 2 times, most recently from c6b3ab4 to e2f99caCompareJuly 26, 2022 07:38
@hf
hfforce-pushed the hf/normalize-redirect-uris branch from e2f99ca to c6e3938CompareJuly 26, 2022 08:01
@kangmingtay
kangmingtay merged commit d6f4a2a into masterJul 26, 2022
@kangmingtay
kangmingtay deleted the hf/normalize-redirect-uris branch July 26, 2022 08:11
@github-actions

Copy link
Copy Markdown
Contributor

🎉 This PR is included in version 2.10.0 🎉

The release is available on GitHub release

Your semantic-release bot 📦🚀

hf added a commit that referenced this pull request Aug 4, 2022
hf added a commit that referenced this pull request Aug 4, 2022
* fix: Revert "fix: don't normalise mobile deeplinks (#591)"
This reverts commit 4042c80.
* fix: Revert "feat: Normalize redirection URLs and globs (#535)"
This reverts commit d6f4a2a.
uxodb pushed a commit to uxodb/auth that referenced this pull request Nov 13, 2024
Co-authored-by: Stojan Dimitrovski <--local>
uxodb pushed a commit to uxodb/auth that referenced this pull request Nov 13, 2024
)
* fix: Revert "fix: don't normalise mobile deeplinks (supabase#591)"
This reverts commit 4042c80.
* fix: Revert "feat: Normalize redirection URLs and globs (supabase#535)"
This reverts commit d6f4a2a.
LashaJini pushed a commit to LashaJini/auth that referenced this pull request Nov 13, 2024
Co-authored-by: Stojan Dimitrovski <--local>
LashaJini pushed a commit to LashaJini/auth that referenced this pull request Nov 13, 2024
)
* fix: Revert "fix: don't normalise mobile deeplinks (supabase#591)"
This reverts commit 4042c80.
* fix: Revert "feat: Normalize redirection URLs and globs (supabase#535)"
This reverts commit d6f4a2a.
LashaJini pushed a commit to LashaJini/auth that referenced this pull request Nov 15, 2024
Co-authored-by: Stojan Dimitrovski <--local>
LashaJini pushed a commit to LashaJini/auth that referenced this pull request Nov 15, 2024
)
* fix: Revert "fix: don't normalise mobile deeplinks (supabase#591)"
This reverts commit 4042c80.
* fix: Revert "feat: Normalize redirection URLs and globs (supabase#535)"
This reverts commit d6f4a2a.
cemalkilic pushed a commit that referenced this pull request Aug 7, 2025
Co-authored-by: Stojan Dimitrovski <--local>
cemalkilic pushed a commit that referenced this pull request Aug 7, 2025
* fix: Revert "fix: don't normalise mobile deeplinks (#591)"
This reverts commit 4042c80.
* fix: Revert "feat: Normalize redirection URLs and globs (#535)"
This reverts commit d6f4a2a.
xeladotbe pushed a commit to xeladotbe/supabase-auth that referenced this pull request Sep 27, 2025
Co-authored-by: Stojan Dimitrovski <--local>
xeladotbe pushed a commit to xeladotbe/supabase-auth that referenced this pull request Sep 27, 2025
)
* fix: Revert "fix: don't normalise mobile deeplinks (supabase#591)"
This reverts commit 4042c80.
* fix: Revert "feat: Normalize redirection URLs and globs (supabase#535)"
This reverts commit d6f4a2a.
fadymak pushed a commit that referenced this pull request Sep 30, 2025
Co-authored-by: Stojan Dimitrovski <--local>
fadymak pushed a commit that referenced this pull request Sep 30, 2025
* fix: Revert "fix: don't normalise mobile deeplinks (#591)"
This reverts commit 4042c80.
* fix: Revert "feat: Normalize redirection URLs and globs (#535)"
This reverts commit d6f4a2a.
@coderabbitaicoderabbitaiBot mentioned this pull request Apr 20, 2026
7 tasks
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@hf@kangmingtay@J0
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat: Normalize redirection URLs and globs - #535

Merged
kangmingtay merged 1 commit into
masterfrom
hf/normalize-redirect-uris
Jul 26, 2022
Merged

feat: Normalize redirection URLs and globs#535
kangmingtay merged 1 commit into
masterfrom
hf/normalize-redirect-uris

Conversation

@hf

@hfhf commented Jul 13, 2022

Copy link
Copy Markdown
Contributor

What kind of change does this PR introduce?

If a user specifies a redirect URL glob of the form:

https://example.com

But they send a redirect_to parameter to /authorize of the form:

https://example.com/

(Note the trailing slash!)

GoTrue will not match the two URLs, even though in the modern web they are equivalent. This PR normalizes HTTP(S) URLs to remove the trailing slash in the redirect_to parameter; as well as ignoring any trailing slashes in the URL allow list.

@hf
hfforce-pushed the hf/normalize-redirect-uris branch from 236f9c4 to 8097a73CompareJuly 13, 2022 09:43

@kangmingtaykangmingtay left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

looks good! but can we also add a test case for this?

Comment threadapi/helpers.go
@hf

hf commented Jul 14, 2022

Copy link
Copy Markdown
ContributorAuthor

looks good! but can we also add a test case for this

Yeah I've been trying to find a way to test it but it's a bit too complex of a case, and the methods have to become public otherwise, so I'm not sure if it's worth it.

@kangmingtay

Copy link
Copy Markdown
Member

@hf you can consider adding it as a test case here

@hf

hf commented Jul 15, 2022

Copy link
Copy Markdown
ContributorAuthor

@hf you can consider adding it as a test case here

Oh that's splendid!

@hf
hfforce-pushed the hf/normalize-redirect-uris branch 3 times, most recently from 2675dd1 to 613ae16CompareJuly 15, 2022 08:41
@hf
hf requested a review from kangmingtayJuly 15, 2022 08:41
@hf
hfforce-pushed the hf/normalize-redirect-uris branch 4 times, most recently from 23d8e11 to a8b78fdCompareJuly 15, 2022 13:55
@hf

hf commented Jul 15, 2022

Copy link
Copy Markdown
ContributorAuthor

@kangmingtay Moving the parsing logic to the configuration doesn't really help much and just duplicates code. I also think it breaks some non-compliant tests as the code has to panic.

Otherwise, I think it's good this way -- the tests are failing because of a rate limit check. I'm trying to find a way to remove it on these tests. Please review again when you can.

@J0

J0 commented Jul 15, 2022

Copy link
Copy Markdown
Contributor

Hmm throwing out ideas here: off the top of head I can think of three suggestions to deal with the rate limiting.

  1. Use build tags for tests

  2. Establish a naming convention for tests with rate limits and then filter tests via regexp like go test -p 1 -v -run '<relevant regexp>'

  3. Gate the rate limiting at api.go with an env var so that it's only enabled when an env var is set to true

    \3. is a little clunky but 1 and 2 would constrain the separation to only tests. Imagine there would be other cases outside of testing (e.g. benchmarks) where we want to turn off rate limiting. If any of the three would be potential solutions lmk and I can file a PR on Sunday or so

Let me know if there are further suggestions or other options we should consider!

Let me also look into our rate limiter lib to see if there's something built in we can use

@kangmingtay

Copy link
Copy Markdown
Member

Moving the parsing logic to the configuration doesn't really help much and just duplicates code.

@hf why can't we just move the parsing logic to the configuration completely so we do it once when the config is loaded? i don't see why it would be duplicated?

@hf
hfforce-pushed the hf/normalize-redirect-uris branch 2 times, most recently from c6b3ab4 to e2f99caCompareJuly 26, 2022 07:38
@hf
hfforce-pushed the hf/normalize-redirect-uris branch from e2f99ca to c6e3938CompareJuly 26, 2022 08:01
@kangmingtay
kangmingtay merged commit d6f4a2a into masterJul 26, 2022
@kangmingtay
kangmingtay deleted the hf/normalize-redirect-uris branch July 26, 2022 08:11
@github-actions

Copy link
Copy Markdown
Contributor

🎉 This PR is included in version 2.10.0 🎉

The release is available on GitHub release

Your semantic-release bot 📦🚀

hf added a commit that referenced this pull request Aug 4, 2022
hf added a commit that referenced this pull request Aug 4, 2022
* fix: Revert "fix: don't normalise mobile deeplinks (#591)"
This reverts commit 4042c80.
* fix: Revert "feat: Normalize redirection URLs and globs (#535)"
This reverts commit d6f4a2a.
uxodb pushed a commit to uxodb/auth that referenced this pull request Nov 13, 2024
Co-authored-by: Stojan Dimitrovski <--local>
uxodb pushed a commit to uxodb/auth that referenced this pull request Nov 13, 2024
)
* fix: Revert "fix: don't normalise mobile deeplinks (supabase#591)"
This reverts commit 4042c80.
* fix: Revert "feat: Normalize redirection URLs and globs (supabase#535)"
This reverts commit d6f4a2a.
LashaJini pushed a commit to LashaJini/auth that referenced this pull request Nov 13, 2024
Co-authored-by: Stojan Dimitrovski <--local>
LashaJini pushed a commit to LashaJini/auth that referenced this pull request Nov 13, 2024
)
* fix: Revert "fix: don't normalise mobile deeplinks (supabase#591)"
This reverts commit 4042c80.
* fix: Revert "feat: Normalize redirection URLs and globs (supabase#535)"
This reverts commit d6f4a2a.
LashaJini pushed a commit to LashaJini/auth that referenced this pull request Nov 15, 2024
Co-authored-by: Stojan Dimitrovski <--local>
LashaJini pushed a commit to LashaJini/auth that referenced this pull request Nov 15, 2024
)
* fix: Revert "fix: don't normalise mobile deeplinks (supabase#591)"
This reverts commit 4042c80.
* fix: Revert "feat: Normalize redirection URLs and globs (supabase#535)"
This reverts commit d6f4a2a.
cemalkilic pushed a commit that referenced this pull request Aug 7, 2025
Co-authored-by: Stojan Dimitrovski <--local>
cemalkilic pushed a commit that referenced this pull request Aug 7, 2025
* fix: Revert "fix: don't normalise mobile deeplinks (#591)"
This reverts commit 4042c80.
* fix: Revert "feat: Normalize redirection URLs and globs (#535)"
This reverts commit d6f4a2a.
xeladotbe pushed a commit to xeladotbe/supabase-auth that referenced this pull request Sep 27, 2025
Co-authored-by: Stojan Dimitrovski <--local>
xeladotbe pushed a commit to xeladotbe/supabase-auth that referenced this pull request Sep 27, 2025
)
* fix: Revert "fix: don't normalise mobile deeplinks (supabase#591)"
This reverts commit 4042c80.
* fix: Revert "feat: Normalize redirection URLs and globs (supabase#535)"
This reverts commit d6f4a2a.
fadymak pushed a commit that referenced this pull request Sep 30, 2025
Co-authored-by: Stojan Dimitrovski <--local>
fadymak pushed a commit that referenced this pull request Sep 30, 2025
* fix: Revert "fix: don't normalise mobile deeplinks (#591)"
This reverts commit 4042c80.
* fix: Revert "feat: Normalize redirection URLs and globs (#535)"
This reverts commit d6f4a2a.
@coderabbitaicoderabbitaiBot mentioned this pull request Apr 20, 2026
7 tasks
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@hf@kangmingtay@J0
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

feat: Normalize redirection URLs and globs - #535

Merged
kangmingtay merged 1 commit into
masterfrom
hf/normalize-redirect-uris
Jul 26, 2022
Merged

feat: Normalize redirection URLs and globs#535
kangmingtay merged 1 commit into
masterfrom
hf/normalize-redirect-uris

Conversation

@hf

@hfhf commented Jul 13, 2022

Copy link
Copy Markdown
Contributor

What kind of change does this PR introduce?

If a user specifies a redirect URL glob of the form:

https://example.com

But they send a redirect_to parameter to /authorize of the form:

https://example.com/

(Note the trailing slash!)

GoTrue will not match the two URLs, even though in the modern web they are equivalent. This PR normalizes HTTP(S) URLs to remove the trailing slash in the redirect_to parameter; as well as ignoring any trailing slashes in the URL allow list.

@hf
hfforce-pushed the hf/normalize-redirect-uris branch from 236f9c4 to 8097a73CompareJuly 13, 2022 09:43

@kangmingtaykangmingtay left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

looks good! but can we also add a test case for this?

Comment threadapi/helpers.go
@hf

hf commented Jul 14, 2022

Copy link
Copy Markdown
ContributorAuthor

looks good! but can we also add a test case for this

Yeah I've been trying to find a way to test it but it's a bit too complex of a case, and the methods have to become public otherwise, so I'm not sure if it's worth it.

@kangmingtay

Copy link
Copy Markdown
Member

@hf you can consider adding it as a test case here

@hf

hf commented Jul 15, 2022

Copy link
Copy Markdown
ContributorAuthor

@hf you can consider adding it as a test case here

Oh that's splendid!

@hf
hfforce-pushed the hf/normalize-redirect-uris branch 3 times, most recently from 2675dd1 to 613ae16CompareJuly 15, 2022 08:41
@hf
hf requested a review from kangmingtayJuly 15, 2022 08:41
@hf
hfforce-pushed the hf/normalize-redirect-uris branch 4 times, most recently from 23d8e11 to a8b78fdCompareJuly 15, 2022 13:55
@hf

hf commented Jul 15, 2022

Copy link
Copy Markdown
ContributorAuthor

@kangmingtay Moving the parsing logic to the configuration doesn't really help much and just duplicates code. I also think it breaks some non-compliant tests as the code has to panic.

Otherwise, I think it's good this way -- the tests are failing because of a rate limit check. I'm trying to find a way to remove it on these tests. Please review again when you can.

@J0

J0 commented Jul 15, 2022

Copy link
Copy Markdown
Contributor

Hmm throwing out ideas here: off the top of head I can think of three suggestions to deal with the rate limiting.

  1. Use build tags for tests

  2. Establish a naming convention for tests with rate limits and then filter tests via regexp like go test -p 1 -v -run '<relevant regexp>'

  3. Gate the rate limiting at api.go with an env var so that it's only enabled when an env var is set to true

    \3. is a little clunky but 1 and 2 would constrain the separation to only tests. Imagine there would be other cases outside of testing (e.g. benchmarks) where we want to turn off rate limiting. If any of the three would be potential solutions lmk and I can file a PR on Sunday or so

Let me know if there are further suggestions or other options we should consider!

Let me also look into our rate limiter lib to see if there's something built in we can use

@kangmingtay

Copy link
Copy Markdown
Member

Moving the parsing logic to the configuration doesn't really help much and just duplicates code.

@hf why can't we just move the parsing logic to the configuration completely so we do it once when the config is loaded? i don't see why it would be duplicated?

@hf
hfforce-pushed the hf/normalize-redirect-uris branch 2 times, most recently from c6b3ab4 to e2f99caCompareJuly 26, 2022 07:38
@hf
hfforce-pushed the hf/normalize-redirect-uris branch from e2f99ca to c6e3938CompareJuly 26, 2022 08:01
@kangmingtay
kangmingtay merged commit d6f4a2a into masterJul 26, 2022
@kangmingtay
kangmingtay deleted the hf/normalize-redirect-uris branch July 26, 2022 08:11
@github-actions

Copy link
Copy Markdown
Contributor

🎉 This PR is included in version 2.10.0 🎉

The release is available on GitHub release

Your semantic-release bot 📦🚀

hf added a commit that referenced this pull request Aug 4, 2022
hf added a commit that referenced this pull request Aug 4, 2022
* fix: Revert "fix: don't normalise mobile deeplinks (#591)"
This reverts commit 4042c80.
* fix: Revert "feat: Normalize redirection URLs and globs (#535)"
This reverts commit d6f4a2a.
uxodb pushed a commit to uxodb/auth that referenced this pull request Nov 13, 2024
Co-authored-by: Stojan Dimitrovski <--local>
uxodb pushed a commit to uxodb/auth that referenced this pull request Nov 13, 2024
)
* fix: Revert "fix: don't normalise mobile deeplinks (supabase#591)"
This reverts commit 4042c80.
* fix: Revert "feat: Normalize redirection URLs and globs (supabase#535)"
This reverts commit d6f4a2a.
LashaJini pushed a commit to LashaJini/auth that referenced this pull request Nov 13, 2024
Co-authored-by: Stojan Dimitrovski <--local>
LashaJini pushed a commit to LashaJini/auth that referenced this pull request Nov 13, 2024
)
* fix: Revert "fix: don't normalise mobile deeplinks (supabase#591)"
This reverts commit 4042c80.
* fix: Revert "feat: Normalize redirection URLs and globs (supabase#535)"
This reverts commit d6f4a2a.
LashaJini pushed a commit to LashaJini/auth that referenced this pull request Nov 15, 2024
Co-authored-by: Stojan Dimitrovski <--local>
LashaJini pushed a commit to LashaJini/auth that referenced this pull request Nov 15, 2024
)
* fix: Revert "fix: don't normalise mobile deeplinks (supabase#591)"
This reverts commit 4042c80.
* fix: Revert "feat: Normalize redirection URLs and globs (supabase#535)"
This reverts commit d6f4a2a.
cemalkilic pushed a commit that referenced this pull request Aug 7, 2025
Co-authored-by: Stojan Dimitrovski <--local>
cemalkilic pushed a commit that referenced this pull request Aug 7, 2025
* fix: Revert "fix: don't normalise mobile deeplinks (#591)"
This reverts commit 4042c80.
* fix: Revert "feat: Normalize redirection URLs and globs (#535)"
This reverts commit d6f4a2a.
xeladotbe pushed a commit to xeladotbe/supabase-auth that referenced this pull request Sep 27, 2025
Co-authored-by: Stojan Dimitrovski <--local>
xeladotbe pushed a commit to xeladotbe/supabase-auth that referenced this pull request Sep 27, 2025
)
* fix: Revert "fix: don't normalise mobile deeplinks (supabase#591)"
This reverts commit 4042c80.
* fix: Revert "feat: Normalize redirection URLs and globs (supabase#535)"
This reverts commit d6f4a2a.
fadymak pushed a commit that referenced this pull request Sep 30, 2025
Co-authored-by: Stojan Dimitrovski <--local>
fadymak pushed a commit that referenced this pull request Sep 30, 2025
* fix: Revert "fix: don't normalise mobile deeplinks (#591)"
This reverts commit 4042c80.
* fix: Revert "feat: Normalize redirection URLs and globs (#535)"
This reverts commit d6f4a2a.
@coderabbitaicoderabbitaiBot mentioned this pull request Apr 20, 2026
7 tasks
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@hf@kangmingtay@J0
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat: Normalize redirection URLs and globs - #535

Merged
kangmingtay merged 1 commit into
masterfrom
hf/normalize-redirect-uris
Jul 26, 2022
Merged

feat: Normalize redirection URLs and globs#535
kangmingtay merged 1 commit into
masterfrom
hf/normalize-redirect-uris

Conversation

@hf

@hfhf commented Jul 13, 2022

Copy link
Copy Markdown
Contributor

What kind of change does this PR introduce?

If a user specifies a redirect URL glob of the form:

https://example.com

But they send a redirect_to parameter to /authorize of the form:

https://example.com/

(Note the trailing slash!)

GoTrue will not match the two URLs, even though in the modern web they are equivalent. This PR normalizes HTTP(S) URLs to remove the trailing slash in the redirect_to parameter; as well as ignoring any trailing slashes in the URL allow list.

@hf
hfforce-pushed the hf/normalize-redirect-uris branch from 236f9c4 to 8097a73CompareJuly 13, 2022 09:43

@kangmingtaykangmingtay left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

looks good! but can we also add a test case for this?

Comment threadapi/helpers.go
@hf

hf commented Jul 14, 2022

Copy link
Copy Markdown
ContributorAuthor

looks good! but can we also add a test case for this

Yeah I've been trying to find a way to test it but it's a bit too complex of a case, and the methods have to become public otherwise, so I'm not sure if it's worth it.

@kangmingtay

Copy link
Copy Markdown
Member

@hf you can consider adding it as a test case here

@hf

hf commented Jul 15, 2022

Copy link
Copy Markdown
ContributorAuthor

@hf you can consider adding it as a test case here

Oh that's splendid!

@hf
hfforce-pushed the hf/normalize-redirect-uris branch 3 times, most recently from 2675dd1 to 613ae16CompareJuly 15, 2022 08:41
@hf
hf requested a review from kangmingtayJuly 15, 2022 08:41
@hf
hfforce-pushed the hf/normalize-redirect-uris branch 4 times, most recently from 23d8e11 to a8b78fdCompareJuly 15, 2022 13:55
@hf

hf commented Jul 15, 2022

Copy link
Copy Markdown
ContributorAuthor

@kangmingtay Moving the parsing logic to the configuration doesn't really help much and just duplicates code. I also think it breaks some non-compliant tests as the code has to panic.

Otherwise, I think it's good this way -- the tests are failing because of a rate limit check. I'm trying to find a way to remove it on these tests. Please review again when you can.

@J0

J0 commented Jul 15, 2022

Copy link
Copy Markdown
Contributor

Hmm throwing out ideas here: off the top of head I can think of three suggestions to deal with the rate limiting.

  1. Use build tags for tests

  2. Establish a naming convention for tests with rate limits and then filter tests via regexp like go test -p 1 -v -run '<relevant regexp>'

  3. Gate the rate limiting at api.go with an env var so that it's only enabled when an env var is set to true

    \3. is a little clunky but 1 and 2 would constrain the separation to only tests. Imagine there would be other cases outside of testing (e.g. benchmarks) where we want to turn off rate limiting. If any of the three would be potential solutions lmk and I can file a PR on Sunday or so

Let me know if there are further suggestions or other options we should consider!

Let me also look into our rate limiter lib to see if there's something built in we can use

@kangmingtay

Copy link
Copy Markdown
Member

Moving the parsing logic to the configuration doesn't really help much and just duplicates code.

@hf why can't we just move the parsing logic to the configuration completely so we do it once when the config is loaded? i don't see why it would be duplicated?

@hf
hfforce-pushed the hf/normalize-redirect-uris branch 2 times, most recently from c6b3ab4 to e2f99caCompareJuly 26, 2022 07:38
@hf
hfforce-pushed the hf/normalize-redirect-uris branch from e2f99ca to c6e3938CompareJuly 26, 2022 08:01
@kangmingtay
kangmingtay merged commit d6f4a2a into masterJul 26, 2022
@kangmingtay
kangmingtay deleted the hf/normalize-redirect-uris branch July 26, 2022 08:11
@github-actions

Copy link
Copy Markdown
Contributor

🎉 This PR is included in version 2.10.0 🎉

The release is available on GitHub release

Your semantic-release bot 📦🚀

hf added a commit that referenced this pull request Aug 4, 2022
hf added a commit that referenced this pull request Aug 4, 2022
* fix: Revert "fix: don't normalise mobile deeplinks (#591)"
This reverts commit 4042c80.
* fix: Revert "feat: Normalize redirection URLs and globs (#535)"
This reverts commit d6f4a2a.
uxodb pushed a commit to uxodb/auth that referenced this pull request Nov 13, 2024
Co-authored-by: Stojan Dimitrovski <--local>
uxodb pushed a commit to uxodb/auth that referenced this pull request Nov 13, 2024
)
* fix: Revert "fix: don't normalise mobile deeplinks (supabase#591)"
This reverts commit 4042c80.
* fix: Revert "feat: Normalize redirection URLs and globs (supabase#535)"
This reverts commit d6f4a2a.
LashaJini pushed a commit to LashaJini/auth that referenced this pull request Nov 13, 2024
Co-authored-by: Stojan Dimitrovski <--local>
LashaJini pushed a commit to LashaJini/auth that referenced this pull request Nov 13, 2024
)
* fix: Revert "fix: don't normalise mobile deeplinks (supabase#591)"
This reverts commit 4042c80.
* fix: Revert "feat: Normalize redirection URLs and globs (supabase#535)"
This reverts commit d6f4a2a.
LashaJini pushed a commit to LashaJini/auth that referenced this pull request Nov 15, 2024
Co-authored-by: Stojan Dimitrovski <--local>
LashaJini pushed a commit to LashaJini/auth that referenced this pull request Nov 15, 2024
)
* fix: Revert "fix: don't normalise mobile deeplinks (supabase#591)"
This reverts commit 4042c80.
* fix: Revert "feat: Normalize redirection URLs and globs (supabase#535)"
This reverts commit d6f4a2a.
cemalkilic pushed a commit that referenced this pull request Aug 7, 2025
Co-authored-by: Stojan Dimitrovski <--local>
cemalkilic pushed a commit that referenced this pull request Aug 7, 2025
* fix: Revert "fix: don't normalise mobile deeplinks (#591)"
This reverts commit 4042c80.
* fix: Revert "feat: Normalize redirection URLs and globs (#535)"
This reverts commit d6f4a2a.
xeladotbe pushed a commit to xeladotbe/supabase-auth that referenced this pull request Sep 27, 2025
Co-authored-by: Stojan Dimitrovski <--local>
xeladotbe pushed a commit to xeladotbe/supabase-auth that referenced this pull request Sep 27, 2025
)
* fix: Revert "fix: don't normalise mobile deeplinks (supabase#591)"
This reverts commit 4042c80.
* fix: Revert "feat: Normalize redirection URLs and globs (supabase#535)"
This reverts commit d6f4a2a.
fadymak pushed a commit that referenced this pull request Sep 30, 2025
Co-authored-by: Stojan Dimitrovski <--local>
fadymak pushed a commit that referenced this pull request Sep 30, 2025
* fix: Revert "fix: don't normalise mobile deeplinks (#591)"
This reverts commit 4042c80.
* fix: Revert "feat: Normalize redirection URLs and globs (#535)"
This reverts commit d6f4a2a.
@coderabbitaicoderabbitaiBot mentioned this pull request Apr 20, 2026
7 tasks
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@hf@kangmingtay@J0
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat: Normalize redirection URLs and globs - #535

Merged
kangmingtay merged 1 commit into
masterfrom
hf/normalize-redirect-uris
Jul 26, 2022
Merged

feat: Normalize redirection URLs and globs#535
kangmingtay merged 1 commit into
masterfrom
hf/normalize-redirect-uris

Conversation

@hf

@hfhf commented Jul 13, 2022

Copy link
Copy Markdown
Contributor

What kind of change does this PR introduce?

If a user specifies a redirect URL glob of the form:

https://example.com

But they send a redirect_to parameter to /authorize of the form:

https://example.com/

(Note the trailing slash!)

GoTrue will not match the two URLs, even though in the modern web they are equivalent. This PR normalizes HTTP(S) URLs to remove the trailing slash in the redirect_to parameter; as well as ignoring any trailing slashes in the URL allow list.

@hf
hfforce-pushed the hf/normalize-redirect-uris branch from 236f9c4 to 8097a73CompareJuly 13, 2022 09:43

@kangmingtaykangmingtay left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

looks good! but can we also add a test case for this?

Comment threadapi/helpers.go
@hf

hf commented Jul 14, 2022

Copy link
Copy Markdown
ContributorAuthor

looks good! but can we also add a test case for this

Yeah I've been trying to find a way to test it but it's a bit too complex of a case, and the methods have to become public otherwise, so I'm not sure if it's worth it.

@kangmingtay

Copy link
Copy Markdown
Member

@hf you can consider adding it as a test case here

@hf

hf commented Jul 15, 2022

Copy link
Copy Markdown
ContributorAuthor

@hf you can consider adding it as a test case here

Oh that's splendid!

@hf
hfforce-pushed the hf/normalize-redirect-uris branch 3 times, most recently from 2675dd1 to 613ae16CompareJuly 15, 2022 08:41
@hf
hf requested a review from kangmingtayJuly 15, 2022 08:41
@hf
hfforce-pushed the hf/normalize-redirect-uris branch 4 times, most recently from 23d8e11 to a8b78fdCompareJuly 15, 2022 13:55
@hf

hf commented Jul 15, 2022

Copy link
Copy Markdown
ContributorAuthor

@kangmingtay Moving the parsing logic to the configuration doesn't really help much and just duplicates code. I also think it breaks some non-compliant tests as the code has to panic.

Otherwise, I think it's good this way -- the tests are failing because of a rate limit check. I'm trying to find a way to remove it on these tests. Please review again when you can.

@J0

J0 commented Jul 15, 2022

Copy link
Copy Markdown
Contributor

Hmm throwing out ideas here: off the top of head I can think of three suggestions to deal with the rate limiting.

  1. Use build tags for tests

  2. Establish a naming convention for tests with rate limits and then filter tests via regexp like go test -p 1 -v -run '<relevant regexp>'

  3. Gate the rate limiting at api.go with an env var so that it's only enabled when an env var is set to true

    \3. is a little clunky but 1 and 2 would constrain the separation to only tests. Imagine there would be other cases outside of testing (e.g. benchmarks) where we want to turn off rate limiting. If any of the three would be potential solutions lmk and I can file a PR on Sunday or so

Let me know if there are further suggestions or other options we should consider!

Let me also look into our rate limiter lib to see if there's something built in we can use

@kangmingtay

Copy link
Copy Markdown
Member

Moving the parsing logic to the configuration doesn't really help much and just duplicates code.

@hf why can't we just move the parsing logic to the configuration completely so we do it once when the config is loaded? i don't see why it would be duplicated?

@hf
hfforce-pushed the hf/normalize-redirect-uris branch 2 times, most recently from c6b3ab4 to e2f99caCompareJuly 26, 2022 07:38
@hf
hfforce-pushed the hf/normalize-redirect-uris branch from e2f99ca to c6e3938CompareJuly 26, 2022 08:01
@kangmingtay
kangmingtay merged commit d6f4a2a into masterJul 26, 2022
@kangmingtay
kangmingtay deleted the hf/normalize-redirect-uris branch July 26, 2022 08:11
@github-actions

Copy link
Copy Markdown
Contributor

🎉 This PR is included in version 2.10.0 🎉

The release is available on GitHub release

Your semantic-release bot 📦🚀

hf added a commit that referenced this pull request Aug 4, 2022
hf added a commit that referenced this pull request Aug 4, 2022
* fix: Revert "fix: don't normalise mobile deeplinks (#591)"
This reverts commit 4042c80.
* fix: Revert "feat: Normalize redirection URLs and globs (#535)"
This reverts commit d6f4a2a.
uxodb pushed a commit to uxodb/auth that referenced this pull request Nov 13, 2024
Co-authored-by: Stojan Dimitrovski <--local>
uxodb pushed a commit to uxodb/auth that referenced this pull request Nov 13, 2024
)
* fix: Revert "fix: don't normalise mobile deeplinks (supabase#591)"
This reverts commit 4042c80.
* fix: Revert "feat: Normalize redirection URLs and globs (supabase#535)"
This reverts commit d6f4a2a.
LashaJini pushed a commit to LashaJini/auth that referenced this pull request Nov 13, 2024
Co-authored-by: Stojan Dimitrovski <--local>
LashaJini pushed a commit to LashaJini/auth that referenced this pull request Nov 13, 2024
)
* fix: Revert "fix: don't normalise mobile deeplinks (supabase#591)"
This reverts commit 4042c80.
* fix: Revert "feat: Normalize redirection URLs and globs (supabase#535)"
This reverts commit d6f4a2a.
LashaJini pushed a commit to LashaJini/auth that referenced this pull request Nov 15, 2024
Co-authored-by: Stojan Dimitrovski <--local>
LashaJini pushed a commit to LashaJini/auth that referenced this pull request Nov 15, 2024
)
* fix: Revert "fix: don't normalise mobile deeplinks (supabase#591)"
This reverts commit 4042c80.
* fix: Revert "feat: Normalize redirection URLs and globs (supabase#535)"
This reverts commit d6f4a2a.
cemalkilic pushed a commit that referenced this pull request Aug 7, 2025
Co-authored-by: Stojan Dimitrovski <--local>
cemalkilic pushed a commit that referenced this pull request Aug 7, 2025
* fix: Revert "fix: don't normalise mobile deeplinks (#591)"
This reverts commit 4042c80.
* fix: Revert "feat: Normalize redirection URLs and globs (#535)"
This reverts commit d6f4a2a.
xeladotbe pushed a commit to xeladotbe/supabase-auth that referenced this pull request Sep 27, 2025
Co-authored-by: Stojan Dimitrovski <--local>
xeladotbe pushed a commit to xeladotbe/supabase-auth that referenced this pull request Sep 27, 2025
)
* fix: Revert "fix: don't normalise mobile deeplinks (supabase#591)"
This reverts commit 4042c80.
* fix: Revert "feat: Normalize redirection URLs and globs (supabase#535)"
This reverts commit d6f4a2a.
fadymak pushed a commit that referenced this pull request Sep 30, 2025
Co-authored-by: Stojan Dimitrovski <--local>
fadymak pushed a commit that referenced this pull request Sep 30, 2025
* fix: Revert "fix: don't normalise mobile deeplinks (#591)"
This reverts commit 4042c80.
* fix: Revert "feat: Normalize redirection URLs and globs (#535)"
This reverts commit d6f4a2a.
@coderabbitaicoderabbitaiBot mentioned this pull request Apr 20, 2026
7 tasks
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@hf@kangmingtay@J0
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

feat: Normalize redirection URLs and globs - #535

Merged
kangmingtay merged 1 commit into
masterfrom
hf/normalize-redirect-uris
Jul 26, 2022
Merged

feat: Normalize redirection URLs and globs#535
kangmingtay merged 1 commit into
masterfrom
hf/normalize-redirect-uris

Conversation

@hf

@hfhf commented Jul 13, 2022

Copy link
Copy Markdown
Contributor

What kind of change does this PR introduce?

If a user specifies a redirect URL glob of the form:

https://example.com

But they send a redirect_to parameter to /authorize of the form:

https://example.com/

(Note the trailing slash!)

GoTrue will not match the two URLs, even though in the modern web they are equivalent. This PR normalizes HTTP(S) URLs to remove the trailing slash in the redirect_to parameter; as well as ignoring any trailing slashes in the URL allow list.

@hf
hfforce-pushed the hf/normalize-redirect-uris branch from 236f9c4 to 8097a73CompareJuly 13, 2022 09:43

@kangmingtaykangmingtay left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

looks good! but can we also add a test case for this?

Comment threadapi/helpers.go
@hf

hf commented Jul 14, 2022

Copy link
Copy Markdown
ContributorAuthor

looks good! but can we also add a test case for this

Yeah I've been trying to find a way to test it but it's a bit too complex of a case, and the methods have to become public otherwise, so I'm not sure if it's worth it.

@kangmingtay

Copy link
Copy Markdown
Member

@hf you can consider adding it as a test case here

@hf

hf commented Jul 15, 2022

Copy link
Copy Markdown
ContributorAuthor

@hf you can consider adding it as a test case here

Oh that's splendid!

@hf
hfforce-pushed the hf/normalize-redirect-uris branch 3 times, most recently from 2675dd1 to 613ae16CompareJuly 15, 2022 08:41
@hf
hf requested a review from kangmingtayJuly 15, 2022 08:41
@hf
hfforce-pushed the hf/normalize-redirect-uris branch 4 times, most recently from 23d8e11 to a8b78fdCompareJuly 15, 2022 13:55
@hf

hf commented Jul 15, 2022

Copy link
Copy Markdown
ContributorAuthor

@kangmingtay Moving the parsing logic to the configuration doesn't really help much and just duplicates code. I also think it breaks some non-compliant tests as the code has to panic.

Otherwise, I think it's good this way -- the tests are failing because of a rate limit check. I'm trying to find a way to remove it on these tests. Please review again when you can.

@J0

J0 commented Jul 15, 2022

Copy link
Copy Markdown
Contributor

Hmm throwing out ideas here: off the top of head I can think of three suggestions to deal with the rate limiting.

  1. Use build tags for tests

  2. Establish a naming convention for tests with rate limits and then filter tests via regexp like go test -p 1 -v -run '<relevant regexp>'

  3. Gate the rate limiting at api.go with an env var so that it's only enabled when an env var is set to true

    \3. is a little clunky but 1 and 2 would constrain the separation to only tests. Imagine there would be other cases outside of testing (e.g. benchmarks) where we want to turn off rate limiting. If any of the three would be potential solutions lmk and I can file a PR on Sunday or so

Let me know if there are further suggestions or other options we should consider!

Let me also look into our rate limiter lib to see if there's something built in we can use

@kangmingtay

Copy link
Copy Markdown
Member

Moving the parsing logic to the configuration doesn't really help much and just duplicates code.

@hf why can't we just move the parsing logic to the configuration completely so we do it once when the config is loaded? i don't see why it would be duplicated?

@hf
hfforce-pushed the hf/normalize-redirect-uris branch 2 times, most recently from c6b3ab4 to e2f99caCompareJuly 26, 2022 07:38
@hf
hfforce-pushed the hf/normalize-redirect-uris branch from e2f99ca to c6e3938CompareJuly 26, 2022 08:01
@kangmingtay
kangmingtay merged commit d6f4a2a into masterJul 26, 2022
@kangmingtay
kangmingtay deleted the hf/normalize-redirect-uris branch July 26, 2022 08:11
@github-actions

Copy link
Copy Markdown
Contributor

🎉 This PR is included in version 2.10.0 🎉

The release is available on GitHub release

Your semantic-release bot 📦🚀

hf added a commit that referenced this pull request Aug 4, 2022
hf added a commit that referenced this pull request Aug 4, 2022
* fix: Revert "fix: don't normalise mobile deeplinks (#591)"
This reverts commit 4042c80.
* fix: Revert "feat: Normalize redirection URLs and globs (#535)"
This reverts commit d6f4a2a.
uxodb pushed a commit to uxodb/auth that referenced this pull request Nov 13, 2024
Co-authored-by: Stojan Dimitrovski <--local>
uxodb pushed a commit to uxodb/auth that referenced this pull request Nov 13, 2024
)
* fix: Revert "fix: don't normalise mobile deeplinks (supabase#591)"
This reverts commit 4042c80.
* fix: Revert "feat: Normalize redirection URLs and globs (supabase#535)"
This reverts commit d6f4a2a.
LashaJini pushed a commit to LashaJini/auth that referenced this pull request Nov 13, 2024
Co-authored-by: Stojan Dimitrovski <--local>
LashaJini pushed a commit to LashaJini/auth that referenced this pull request Nov 13, 2024
)
* fix: Revert "fix: don't normalise mobile deeplinks (supabase#591)"
This reverts commit 4042c80.
* fix: Revert "feat: Normalize redirection URLs and globs (supabase#535)"
This reverts commit d6f4a2a.
LashaJini pushed a commit to LashaJini/auth that referenced this pull request Nov 15, 2024
Co-authored-by: Stojan Dimitrovski <--local>
LashaJini pushed a commit to LashaJini/auth that referenced this pull request Nov 15, 2024
)
* fix: Revert "fix: don't normalise mobile deeplinks (supabase#591)"
This reverts commit 4042c80.
* fix: Revert "feat: Normalize redirection URLs and globs (supabase#535)"
This reverts commit d6f4a2a.
cemalkilic pushed a commit that referenced this pull request Aug 7, 2025
Co-authored-by: Stojan Dimitrovski <--local>
cemalkilic pushed a commit that referenced this pull request Aug 7, 2025
* fix: Revert "fix: don't normalise mobile deeplinks (#591)"
This reverts commit 4042c80.
* fix: Revert "feat: Normalize redirection URLs and globs (#535)"
This reverts commit d6f4a2a.
xeladotbe pushed a commit to xeladotbe/supabase-auth that referenced this pull request Sep 27, 2025
Co-authored-by: Stojan Dimitrovski <--local>
xeladotbe pushed a commit to xeladotbe/supabase-auth that referenced this pull request Sep 27, 2025
)
* fix: Revert "fix: don't normalise mobile deeplinks (supabase#591)"
This reverts commit 4042c80.
* fix: Revert "feat: Normalize redirection URLs and globs (supabase#535)"
This reverts commit d6f4a2a.
fadymak pushed a commit that referenced this pull request Sep 30, 2025
Co-authored-by: Stojan Dimitrovski <--local>
fadymak pushed a commit that referenced this pull request Sep 30, 2025
* fix: Revert "fix: don't normalise mobile deeplinks (#591)"
This reverts commit 4042c80.
* fix: Revert "feat: Normalize redirection URLs and globs (#535)"
This reverts commit d6f4a2a.
@coderabbitaicoderabbitaiBot mentioned this pull request Apr 20, 2026
7 tasks
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@hf@kangmingtay@J0