Skip to content

Conversation

@kjac
Copy link
Contributor

@kjac kjac commented Nov 17, 2025

Prerequisites

  • I have added steps to test this contribution in the description below

Description

This is #20847, cherry-picked for V16 where the cookie handling is optional.

Testing

See #20847 for test info. Remember to enable cookies in tokens - see #20779 for configuration details.

* Redact back-office PKCE codes from the server

* Update src/Umbraco.Cms.Api.Common/DependencyInjection/HideBackOfficeTokensHandler.cs

---------

Co-authored-by: Andy Butland <[email protected]>
Copy link
Contributor

@AndyButland AndyButland left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks @kjac - works as expected, and has no effect unless the configuration option is enabled.

@kjac kjac merged commit 590a020 into release/16.4 Nov 17, 2025
22 of 23 checks passed
@kjac kjac deleted the v16/feature/redact-pkce-code branch November 17, 2025 10:17
@iOvergaard iOvergaard changed the title Redact back-office PKCE codes from the server (V16) Backoffice Login: Redact back-office PKCE codes from the server (V16) Nov 17, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants