From 10c779bbc6b50e7eaca813fa920f0c083c275b15 Mon Sep 17 00:00:00 2001 From: Christian Grothoff Date: Sun, 16 Apr 2023 21:25:48 +0200 Subject: add FIXME --- src/kyclogic/plugin_kyclogic_oauth2.c | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/src/kyclogic/plugin_kyclogic_oauth2.c b/src/kyclogic/plugin_kyclogic_oauth2.c index d4aaf4494..228525e28 100644 --- a/src/kyclogic/plugin_kyclogic_oauth2.c +++ b/src/kyclogic/plugin_kyclogic_oauth2.c @@ -514,6 +514,11 @@ initiate_task (void *cls) pd->client_id, redirect_uri_encoded); GNUNET_free (redirect_uri_encoded); + /* FIXME-API: why do we *redirect* the client here, + instead of making the HTTP request *ourselves* + and forwarding the response? This prevents us + from using authentication on initiation, + (which is desirable for challenger!) */ ih->cb (ih->cb_cls, TALER_EC_NONE, url, -- cgit v1.2.3