Check whether the outcome improved
Define callback outcomes
Write expected result for matching URI and state, trailing-slash difference, wrong host, wrong environment, missing state, expired session, and duplicate callback. State whether exchange is attempted, which local state is created, and what recovery is shown.
Run URI and state matrix
Execute fixtures through authorization request, callback, state validation, and exchange. Confirm exact registered values are required and state cannot be reused across attempts. Check that failures retain no code or token in visible output or logs.
Exercise session recovery
Refresh, restart, and repeat a callback after session expiry or an already-used state. Verify the flow returns to a safe start without accepting an unknown response. Test a nearby environment configuration with synthetic registration values.
What to carry forward
Accept when exact URI and state pairs complete the intended session, altered or stale callbacks stop safely, and sensitive values stay protected. Keep external exchange coverage partial when uncontrolled. Record matrix, registrations, client revision, and recovery outcomes.
Technical background: RFC Editor reference.
Keep the decision with the work.
Use a Work Item in Aglet to record the problem, the evidence you have, and the next decision. Add an owner and priority, then keep updates in the discussion so the next person can follow the reasoning.
Create an account See the product workflow