Keep the lesson for the next incident
Document callback rules
Record exact redirect URI, environment, state lifetime, session binding, duplicate handling, exchange boundary, recovery route, and owner. Define the safe result for unknown host, missing state, expired session, and used callback.
Keep safe flow fixtures
Retain matching, slash, wrong-host, wrong-environment, missing-state, expired, duplicate, and restart cases with synthetic values. Store expected session and exchange state. Remove no boundary fixture simply because the current registration is stable.
Review registration changes
Watch host or path changes, callback failures, state reuse, expired sessions, and exchange errors by client and environment. Assign an owner and threshold. Close the follow-up only when each configured registration has matching flow coverage.
What to carry forward
Close learning with callback rules, synthetic fixtures, registration and session owners, and recurrence signals. Keep external exchange limits visible. The durable outcome is an exact, reviewable recovery path when a redirect changes again. Keep the callback boundary explicit during host changes.
Technical background: RFC Editor reference.
Keep the decision with the work.
Use a Work Item in Aglet to record the problem, the evidence you have, and the next decision. Add an owner and priority, then keep updates in the discussion so the next person can follow the reasoning.
Create an account See the product workflow