Skip to main content

OAuth2 authorization code failed

OAuth2 authorization code flow not working. State value is not required, but testfully adding it before sending the request

Status: Completed4 comments

Log in to comment and vote

Comments4

  • testfully

    Team•

    Jul 9, 2024

    Hi @srinivas gogineni

    Thanks for lodging this issue. I just had a look at the implementation and can confirm that the invalid_request: missing ‘state’ query param is returned by Testfully when the URL does not have the expected state Query param.

    > State value is not required, but testfully adding it before sending the request.
    I need to investigate if this field is meant to be mandatory or not, but given that Testfully does send a state param to your OAuth2 server, we do expect it to be returned for better security posture.

    Do you use one of industry-standard OAuth2 providers (SaaS, framework etc) or are you building a OAuth2 server on your end?

    • srinivas gogineni

      •

      Jul 12, 2024

      For saml assertion app will generate state value. Before it expects empty state value to pass in the request

      • testfully

        Team•

        Jul 18, 2024

        Hi @srinivas gogineni

        Thanks for being patient while we looked into this issue. This issue will be fixed as part of the next release.

        • testfully

          Team•

          Jul 18, 2024

          @srinivas gogineni

          This issue is being fixed. We just released Testfully 1.137.0