Replies: 1 comment
-
Hey Cameron, |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
Related to #1021
Right now, hydra requires explicitly enabling http urls using the
dangerous-allow-insecure-redirect-urls
CLI parameter unless using a.localhost
domain.Our local setup chose to use
.test
over.localhost
a long time ago, so this causes a bit of friction.Given
.localhost
comes from RFC 2606, I'd like to propose adding.test
as an enabled-by-default http callback URL, since it's also a reserved TLD used for testing.I don't think it'd make sense to do this for
.invalid
or.example
since they aren't intended for running code.Beta Was this translation helpful? Give feedback.
All reactions