fix(auth): thread use_https into the native password-login PKCE clear

Merging main brought in the RFC 8252 native sign-in path for password
providers (#75808), added while this PR was open. Its loopback-code
branch calls clear_pkce_cookie() without use_https, which is now a
required keyword-only argument — so /auth/native/password-login raised
TypeError on the success path.

This is the same call-site class the PR already fixed at the other three
sites: the deletion must mirror the shape the setter emitted for the
active origin, or the browser keeps the stale PKCE cookie.

Caught by CI running the merge commit against main's newer
test_dashboard_auth_native_flow.py suite, which does not exist on the
branch. Three tests failed there and pass with this change.
This commit is contained in:
Ben Barclay
2026-08-24 16:58:51 +10:00
parent 9a91f7058c
commit 53ab03dc4d
+1 -1
View File
@@ -854,7 +854,7 @@ async def auth_password_login(request: Request, body: _PasswordLoginBody):
# this window" page. No session cookies: the desktop is not a
# browser session (mirrors the /auth/callback native branch).
resp = JSONResponse({"ok": True, "next": loopback})
clear_pkce_cookie(resp, prefix=_prefix(request))
clear_pkce_cookie(resp, use_https=detect_https(request), prefix=_prefix(request))
return resp
expires_in = max(60, session.expires_at - int(time.time()))