fix(auth): thread use_https into the native password-login PKCE clear
Merging main brought in the RFC 8252 native sign-in path for password providers (#75808), added while this PR was open. Its loopback-code branch calls clear_pkce_cookie() without use_https, which is now a required keyword-only argument — so /auth/native/password-login raised TypeError on the success path. This is the same call-site class the PR already fixed at the other three sites: the deletion must mirror the shape the setter emitted for the active origin, or the browser keeps the stale PKCE cookie. Caught by CI running the merge commit against main's newer test_dashboard_auth_native_flow.py suite, which does not exist on the branch. Three tests failed there and pass with this change.
This commit is contained in:
@@ -854,7 +854,7 @@ async def auth_password_login(request: Request, body: _PasswordLoginBody):
|
||||
# this window" page. No session cookies: the desktop is not a
|
||||
# browser session (mirrors the /auth/callback native branch).
|
||||
resp = JSONResponse({"ok": True, "next": loopback})
|
||||
clear_pkce_cookie(resp, prefix=_prefix(request))
|
||||
clear_pkce_cookie(resp, use_https=detect_https(request), prefix=_prefix(request))
|
||||
return resp
|
||||
|
||||
expires_in = max(60, session.expires_at - int(time.time()))
|
||||
|
||||
Reference in New Issue
Block a user