View Issue Details

IDProjectCategoryView StatusLast Update
0009710Talerexchangepublic2025-04-08 19:19
ReporterChristian Grothoff Assigned To 
PrioritynormalSeverityfeatureReproducibilityN/A
Status confirmedResolutionopen 
Platformi7OSDebian GNU/LinuxOS Versionsqueeze
Product Versiongit (master) 
Target Versionpost-1.0 
Summary0009710: post-kyc redirect is suboptimal
DescriptionAfter KYC, redirected to 'thank you' page, but there may be new/further requirements on the 'main' KYC page.
So instead of going to the 'thank you' page, we should redirect to the KYC info page.
TagsNo tags attached.

Activities

Christian Grothoff

2025-04-08 17:50

manager   ~0024445

There is a security issue here, which is that when the user visits the OAuth2.0 "proof" page we cannot exactly be sure it's the legitimate user (for example, the URL seems harmless and might be shared with a 3rd party by accident). In that case, we might not want to just redirect to the /kyc-info/ page where the URL includes a secret key. Or do we consider this OK? Needs security review before implementation!

Issue History

Date Modified Username Field Change
2025-04-08 17:37 Christian Grothoff New Issue
2025-04-08 17:37 Christian Grothoff Status new => assigned
2025-04-08 17:37 Christian Grothoff Assigned To => Christian Grothoff
2025-04-08 17:48 Christian Grothoff Target Version 1.0 => post-1.0
2025-04-08 17:50 Christian Grothoff Note Added: 0024445
2025-04-08 19:19 Christian Grothoff Assigned To Christian Grothoff =>
2025-04-08 19:19 Christian Grothoff Status assigned => confirmed