Aglet

Learn from OAuth redirect mismatches

The durable lesson is a callback contract that binds URI, environment, state, browser session, and exchange. Preserve the mismatch and the literal comparison that resolved it. Keep external authorization and code-exchange boundaries explicit. Document each registered environment and preserve the exact redirect comparison during later configuration changes.

Keep the lesson for the next incident

  1. Document callback rules

    Record exact redirect URI, environment, state lifetime, session binding, duplicate handling, exchange boundary, recovery route, and owner. Define the safe result for unknown host, missing state, expired session, and used callback.

  2. Keep safe flow fixtures

    Retain matching, slash, wrong-host, wrong-environment, missing-state, expired, duplicate, and restart cases with synthetic values. Store expected session and exchange state. Remove no boundary fixture simply because the current registration is stable.

  3. Review registration changes

    Watch host or path changes, callback failures, state reuse, expired sessions, and exchange errors by client and environment. Assign an owner and threshold. Close the follow-up only when each configured registration has matching flow coverage.

What to carry forward

Close learning with callback rules, synthetic fixtures, registration and session owners, and recurrence signals. Keep external exchange limits visible. The durable outcome is an exact, reviewable recovery path when a redirect changes again. Keep the callback boundary explicit during host changes.

Technical background: RFC Editor reference.

Keep the decision with the work.

Use a Work Item in Aglet to record the problem, the evidence you have, and the next decision. Add an owner and priority, then keep updates in the discussion so the next person can follow the reasoning.

Create an account See the product workflow