[openstreetmap/openstreetmap-website] Add localhost to allowed http redirect_uris for OAuth (PR #4287)

Tom Hughes notifications at github.com
Tue Oct 24 12:43:31 UTC 2023


I wouldn't say there is no interest - clearly there is interest.

The only concern is the potential impact on security.

Even if we allowed `localhost` though I don't think we would want to extend that to other names and in a sense what you're trying to do is exactly the kind of thing we want to protect against, with requests being redirected into different environments.

-- 
Reply to this email directly or view it on GitHub:
https://github.com/openstreetmap/openstreetmap-website/pull/4287#issuecomment-1777133048
You are receiving this because you are subscribed to this thread.

Message ID: <openstreetmap/openstreetmap-website/pull/4287/c1777133048 at github.com>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.openstreetmap.org/pipermail/rails-dev/attachments/20231024/ea361632/attachment.htm>


More information about the rails-dev mailing list