Skip to content

OAuth redirect parsing can crash on malformed callback URLs #2671

Description

Steps to reproduce

Complete a login flow that returns an unexpected redirect URL, especially one with no query string or malformed parameters.

Expected behavior

The app should reject the callback cleanly and show a readable login error.

Actual behavior

The redirect query parser assumes every pair contains =, so malformed URLs can crash the login flow.

Cloudstream version and commit hash

4.7.0-PRE c31c576

Android version

Android 14

Logcat

Other details

No response

Acknowledgements

  • I am sure my issue is related to the app and NOT some extension.
  • I have searched the existing issues and this is a new ticket, NOT a duplicate or related to another open issue.
  • I have written a short but informative title.
  • I have updated the app to pre-release version Latest.
  • I will fill out all of the requested information in this form.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions