Skip to content

Use https scheme for OAuth redirects #240

Description

@DeD1rk

Using https instead of nu.thalia as scheme for OAuth redirects is more secure, since both iOS and Android require a web server to declare that they some app is allowed to listen to its https redirects.

For #239, we have to do this as TOSTI doesn't allow non-https redirects, but for concrexit it also seems like a good idea.

See https://developer.android.com/training/app-links/verify-site-associations

Metadata

Metadata

Assignees

No one assigned

    Labels

    choreSomething that is not a bug or a feature, does not change production behaviourpriority: maybe somedayThis is not really relevant, but if we have nothing else to do, then we can think about this.

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions