• 
      

    Bring over improvements made to the client login flow in RBCommons.

    Review Request #15320 — Created Sept. 17, 2026 and submitted

    Information

    Review Board
    release-9.x

    Reviewers

    RBCommons 8 added support for the client login flow, which was released
    in Review Board 5.0.5. RBCommons needed some special handling in order
    to make things work with it's two-factor authentication. While working
    on that, some improvements to the general client login flow code were made:

    • Guarding against a client url that has an invalid port.
    • Encoding the client name, client URL query strings.
    • Adding more unit tests.

    This change brings those in to the Review Board client login flow. While
    here I noticed the centering for the messages after success/failed client
    log ins got affected from some changes to our auth forms CSS, so this
    addresses that too.

    • Ran unit tests.
    • Tested the client login flow while logged in and
      logged out.
    Summary ID
    Bring over improvements made to the client login flow in RBCommons.
    RBCommons 8 added support for the client login flow, which was released in Review Board 5.0.5. RBCommons needed some special handling in order to make things work with it's two-factor authentication. While working on that, some improvements to the general client login flow code were made: - Guarding against a client url that has an invalid port. - Encoding the client name, client URL query strings. - Adding more unit tests. This change brings those in to the Review Board client login flow.
    437b7f4da8d48754d1e2722c64f0049b81d76ee0
    Description From Last Updated

    Inclead of clearing out client_url for the if below, we can use try/except/else: try: client_url_port = urlparse(client_url).port except ValueError: # …

    david david

    We have another un-guarded urlparse call here.

    david david

    We need to add quoting here too.

    david david

    We need to add quoting here too.

    david david
    david
    1. 
        
    2. reviewboard/accounts/views.py (Diff revision 1)
       
       
       
       
       
       
       
       
       
       
       
       
      Show all issues

      Inclead of clearing out client_url for the if below, we can use try/except/else:

      try:
          client_url_port = urlparse(client_url).port
      except ValueError:
          # The request is malformed. Ignore the client login flow.
          pass
      else:
          self.client_name = client_name
          ...
      
    3. reviewboard/accounts/views.py (Diff revision 1)
       
       
      Show all issues

      We have another un-guarded urlparse call here.

    4. reviewboard/accounts/views.py (Diff revision 1)
       
       
       
       
       
       
       
       
       
       
       
      Show all issues

      We need to add quoting here too.

    5. reviewboard/accounts/views.py (Diff revision 1)
       
       
      Show all issues

      We need to add quoting here too.

    6. 
        
    maubin
    david
    1. Ship It!
    2. 
        
    maubin
    Review request changed
    Status:
    Completed
    Change Summary:
    Pushed to release-9.x (99ff7cf)