Skip to content

Support HTTPS links as redirect URLs on iOS 17.4+ - #978

Merged
w-goog merged 5 commits into
openid:masterfrom
KhaleelSH:aswebauthenticationsession-update-init-method-ios
Sep 24, 2026
Merged

w-goog merged 5 commits into
openid:masterfrom
KhaleelSH:aswebauthenticationsession-update-init-method-ios

Conversation

@KhaleelSH

Copy link
Copy Markdown
Contributor

Supersedes #938, rebased onto 3.0.0 and updated for @w-goog's review there.

For iOS 17.4+, when the redirect URL is an HTTPS universal link, use ASWebAuthenticationSession's HTTPS callback instead of a custom scheme callback.

For iOS, when version 17.4+ is available, check whether the redirect url
is a universal link. If it is, use the new init method with callback
accepting the universal link.
@KhaleelSH KhaleelSH changed the title Aswebauthenticationsession update init method ios Support HTTPS universal links as redirect URLs on iOS 17.4+ Sep 14, 2026
@KhaleelSH
KhaleelSH force-pushed the aswebauthenticationsession-update-init-method-ios branch from 128a00c to 09cbc59 Compare September 14, 2026 23:23
@KhaleelSH KhaleelSH changed the title Support HTTPS universal links as redirect URLs on iOS 17.4+ Support HTTPS links as redirect URLs on iOS 17.4+ Sep 16, 2026

@w-goog w-goog left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The README says "Both Custom URI Schemes and Universal Links can be used with the library.". That hasn't been true for a while - thank you for fixing it!

Also, please add "iOS 17.4+, requires the Associated Domains entitlement and an AASA file for the host" to that line of the README :)

Comment thread AppAuth.xcodeproj/project.pbxproj Outdated
Comment thread Sources/AppAuth/iOS/OIDExternalUserAgentIOS.m Outdated
Comment thread Sources/AppAuth/iOS/OIDExternalUserAgentIOS.m Outdated
Comment thread Sources/AppAuth/iOS/OIDExternalUserAgentIOS.m Outdated
Comment thread Sources/AppAuth/iOS/OIDExternalUserAgentIOS.m Outdated
Comment thread UnitTests/OIDExternalUserAgentIOSTests.m Outdated
@KhaleelSH

Copy link
Copy Markdown
Contributor Author

Thanks for the review! All addressed.

I added webcredentials to your wording, since the HTTPS callback needs the host under that service and apps with only applinks: won't work.

Also one behavior change to flag: the shared handler checks the result of resumeExternalUserAgentFlowWithURL:error: and fails the flow when it returns NO. ASWebAuthenticationSession matches callbacks more loosely than the flow does (a custom scheme matches on the scheme alone, and HTTPS ignores case and the port), so a mismatched redirect used to leave the flow hanging. It now fails with OIDErrorCodeURLMismatch, on the custom scheme path too. Happy to limit that to HTTPS if you'd prefer.

@KhaleelSH
KhaleelSH requested a review from w-goog September 23, 2026 22:09

@w-goog w-goog left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good! I updated the language around universal links, since they are technically just HTTPS URLs.

@w-goog
w-goog merged commit fed71b8 into openid:master Sep 24, 2026
16 checks passed
@w-goog w-goog mentioned this pull request Sep 24, 2026
@KhaleelSH
KhaleelSH deleted the aswebauthenticationsession-update-init-method-ios branch September 24, 2026 19:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants