(In reply to Toby Pilling [:tobyp] from comment #16) > If the redirect_uri (and the nested one that's part of the `done` parameter) is http://localhost it fails - but if I change that to https it works... > > https://login.yahoo.com/?src=thunderbird&client_id=dj0yJmk9NUtCTWFMNVpTaVJmJmQ9WVdrOVJ6UjVTa2xJTXpRbWNHbzlNQS0tJnM9Y29uc3VtZXJzZWNyZXQmeD0yYw--&crumb=.Bj6LTeic6E&login_hint=email%40yahoo.com&redirect_uri=https%3A%2F%2Flocalhost&pspid=954010027&activity=thunderbird-imap&done=https%3A%2F%2Fapi.login.yahoo.com%2Foauth2%2Fauthorize%3F.scrumb%3D0%26client_id%3Ddj0yJmk9NUtCTWFMNVpTaVJmJmQ9WVdrOVJ6UjVTa2xJTXpRbWNHbzlNQS0tJnM9Y29uc3VtZXJzZWNyZXQmeD0yYw--%26redirect_uri%3Dhttps%253A%252F%252Flocalhost%26response_type%3Dcode%26scope%3Dmail-w > > vs > > https://login.yahoo.com/?src=thunderbird&client_id=dj0yJmk9NUtCTWFMNVpTaVJmJmQ9WVdrOVJ6UjVTa2xJTXpRbWNHbzlNQS0tJnM9Y29uc3VtZXJzZWNyZXQmeD0yYw--&crumb=.Bj6LTeic6E&login_hint=email%40yahoo.com&redirect_uri=http%3A%2F%2Flocalhost&pspid=954010027&activity=thunderbird-imap&done=https%3A%2F%2Fapi.login.yahoo.com%2Foauth2%2Fauthorize%3F.scrumb%3D0%26client_id%3Ddj0yJmk9NUtCTWFMNVpTaVJmJmQ9WVdrOVJ6UjVTa2xJTXpRbWNHbzlNQS0tJnM9Y29uc3VtZXJzZWNyZXQmeD0yYw--%26redirect_uri%3Dhttp%253A%252F%252Flocalhost%26response_type%3Dcode%26scope%3Dmail-w If it's just a matter of http:// vs https:// it sounds like we could just update `OAuth2Providers.sys.mjs` to set an https redirection endpoint like we do for Microsoft [here](https://searchfox.org/comm-central/rev/6f68b6c11cf586f8ac2fb2f70481f0e17da88cab/mailnews/base/src/OAuth2Providers.sys.mjs#192)?
Bug 1997062 Comment 18 Edit History
Note: The actual edited comment in the bug view page will always show the original commenter’s name and original timestamp.
(In reply to Toby Pilling [:tobyp] from comment #16) > If the redirect_uri (and the nested one that's part of the `done` parameter) is http://localhost it fails - but if I change that to https it works... > > https://login.yahoo.com/?src=thunderbird&client_id=dj0yJmk9NUtCTWFMNVpTaVJmJmQ9WVdrOVJ6UjVTa2xJTXpRbWNHbzlNQS0tJnM9Y29uc3VtZXJzZWNyZXQmeD0yYw--&crumb=.Bj6LTeic6E&login_hint=email%40yahoo.com&redirect_uri=https%3A%2F%2Flocalhost&pspid=954010027&activity=thunderbird-imap&done=https%3A%2F%2Fapi.login.yahoo.com%2Foauth2%2Fauthorize%3F.scrumb%3D0%26client_id%3Ddj0yJmk9NUtCTWFMNVpTaVJmJmQ9WVdrOVJ6UjVTa2xJTXpRbWNHbzlNQS0tJnM9Y29uc3VtZXJzZWNyZXQmeD0yYw--%26redirect_uri%3Dhttps%253A%252F%252Flocalhost%26response_type%3Dcode%26scope%3Dmail-w > > vs > > https://login.yahoo.com/?src=thunderbird&client_id=dj0yJmk9NUtCTWFMNVpTaVJmJmQ9WVdrOVJ6UjVTa2xJTXpRbWNHbzlNQS0tJnM9Y29uc3VtZXJzZWNyZXQmeD0yYw--&crumb=.Bj6LTeic6E&login_hint=email%40yahoo.com&redirect_uri=http%3A%2F%2Flocalhost&pspid=954010027&activity=thunderbird-imap&done=https%3A%2F%2Fapi.login.yahoo.com%2Foauth2%2Fauthorize%3F.scrumb%3D0%26client_id%3Ddj0yJmk9NUtCTWFMNVpTaVJmJmQ9WVdrOVJ6UjVTa2xJTXpRbWNHbzlNQS0tJnM9Y29uc3VtZXJzZWNyZXQmeD0yYw--%26redirect_uri%3Dhttp%253A%252F%252Flocalhost%26response_type%3Dcode%26scope%3Dmail-w If it's just a matter of http:// vs https:// maybe we could just update `OAuth2Providers.sys.mjs` to set an https redirection endpoint like we do for Microsoft [here](https://searchfox.org/comm-central/rev/6f68b6c11cf586f8ac2fb2f70481f0e17da88cab/mailnews/base/src/OAuth2Providers.sys.mjs#192)?