From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from gate001.proxmox.com (gate001.proxmox.com [45.144.208.40]) by lore.proxmox.com (Postfix) with ESMTPS id 4F25E1FF0A8 for ; Thu, 20 Aug 2026 16:29:03 +0200 (CEST) Received: from gate001.proxmox.com (localhost.localdomain [127.0.0.1]) by gate001.proxmox.com (Proxmox) with ESMTP id CE497215D0; Thu, 20 Aug 2026 16:29:00 +0200 (CEST) Mime-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset=UTF-8 Date: Thu, 20 Aug 2026 16:28:55 +0200 Message-Id: From: "Shan Shaji" To: "Azharul Haque" , Subject: Re: [PATCH login-manager v2 3/3] fix #4281: ui: use a namespaced OpenID callback scheme X-Mailer: aerc 0.20.0 References: <20260810144713.75806-1-haque@azharul.com> <20260810144713.75806-6-haque@azharul.com> In-Reply-To: <20260810144713.75806-6-haque@azharul.com> X-Bm-Milter-Handled: 55990f41-d878-4baa-be0a-ee34c49e34d2 X-Bm-Transport-Timestamp: 1787236109916 X-SPAM-LEVEL: Spam detection results: 0 AWL -0.570 Adjusted score from AWL reputation of From: address DMARC_MISSING 0.1 Missing DMARC policy KAM_DMARC_STATUS 0.01 Test Rule for DKIM or SPF Failure with Strict Alignment (newer systems) RCVD_IN_DNSWL_MED -2.3 Sender listed at https://www.dnswl.org/, medium trust SPF_HELO_NONE 0.001 SPF: HELO does not publish an SPF Record SPF_PASS -0.001 SPF: sender matches SPF record Message-ID-Hash: 2AVCUVD2A5GLP6DSL3VX3XHMNXHC2ALI X-Message-ID-Hash: 2AVCUVD2A5GLP6DSL3VX3XHMNXHC2ALI X-MailFrom: s.shaji@proxmox.com X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; loop; banned-address; emergency; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header X-Mailman-Version: 3.3.10 Precedence: list List-Id: Proxmox VE development discussion List-Help: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: On Mon Aug 10, 2026 at 4:47 PM CEST, Azharul Haque wrote: > pveauth:// worked in testing, but on Android a custom URL scheme > isn't exclusively owned the way a verified App Link is: any other > app installed on the device could in principle also declare an > intent-filter for the same short, guessable scheme. > > Use com.proxmox.app.openid instead, derived from the app's own > package/bundle identifier (com.proxmox.*, reserved for Proxmox on > both app stores), so collisions with another app's scheme are > effectively ruled out rather than merely unlikely. > > Signed-off-by: Azharul Haque > --- > lib/proxmox_login_form.dart | 6 +++++- > 1 file changed, 5 insertions(+), 1 deletion(-) > > diff --git a/lib/proxmox_login_form.dart b/lib/proxmox_login_form.dart > index 002838c..c5ea090 100644 > --- a/lib/proxmox_login_form.dart > +++ b/lib/proxmox_login_form.dart > @@ -17,7 +17,11 @@ import 'package:proxmox_login_manager/proxmox_password= _store.dart'; > /// OpenID Connect login completes. Must be registered as a valid redire= ct > /// URI with the realm's provider, as well as in the platform manifests > /// (AndroidManifest.xml / Info.plist). > -const String openIdCallbackScheme =3D 'pveauth'; > +/// > +/// Derived from the app's own package/bundle identifier (`com.proxmox.*= `, > +/// reserved for Proxmox on both app stores) rather than an arbitrary wo= rd, > +/// so it can't collide with another app's custom URL scheme. > +const String openIdCallbackScheme =3D 'com.proxmox.app.openid'; Also, IMHO the scheme could just be (com.proxmox.app). I don't think it has to be specific for openid. Sorry, missed to mention this in the earlier replies.=20 =20 > class ProxmoxProgressModel { > int inProgress =3D 0;