Uploaded image for project: 'Crowd Data Center'
  1. Crowd Data Center
  2. CWD-3347

Email address with '+' character breaks OpenID flow

    XMLWordPrintable

Details

    Description

      I attempted to purchase an item from the Atlassian store. After clicking 'checkout', I was pushed to the OpenID host for authentication. I successfully logged in and was redirected back to the store host, which redirected me back to the OpenID host and the redirect loop continued until I stopped it after 5 minutes.

      Steps to reproduce
      1. (Optional) Create an OpenID profile on https://openid.atlassian.com using a + character in the email address.
      2. Visit the Atlassian store
        1. Add an item to your cart.
        2. Click 'checkout'.
      3. (Optional, if you did not create an OpenID profile above) Create an OpenID profile on https://openid.atlassian.com using a + character in the email address.
      4. Enter the redirect loop.

      Attachments

        Issue Links

          Activity

            People

              jwalton joe
              6bf546028907 Sasha Gerrand
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: