Problem

RedirectInteraction::respond() hands the visitor to the configured external URL with new RedirectResponse(Url::fromUri($url, $options)->toString()). Core's RedirectResponseSubscriber::checkRedirectUrl() replaces every redirect that leaves the host and is not a SecuredRedirectResponse with a 400 reading "Redirects to external URLs are not allowed by default, use TrustedRedirectResponse", and logs an error each time. So the one thing this plugin exists to do, send a party to a partner site, a document signer or an off-site form, never happens in a browser: the visitor reads a core error sentence on the public dispatcher route, and the site log fills with one error line per visit. Only a same-host destination works, which is not what the plugin is for.

RedirectInteractionTest reads getTargetUrl() off the response the plugin built, which is the plugin's intention rather than what the browser receives, so the subscriber that rewrites it never ran in the test.

Every other new RedirectResponse( in the project points at this site (the comment page, a webform's canonical page, the content task route, the inbox, the signal routes), so this is the one door affected.

Steps to reproduce

Give a wait node the Redirect interaction with the URL https://example.com/sign, start the run, follow the capability link. The response is a 400, not a redirect.

Proposed resolution

Return a TrustedRedirectResponse. It is cacheable, and the step route already declares no_cache: TRUE, so nothing else changes. Test by putting the response through redirect_response_subscriber->checkRedirectUrl() on a ResponseEvent, the way core does, and asserting the event still carries a redirect to the configured host; without the fix the event carries the 400.

AI disclosure: this issue was drafted by Claude Code from an automated file-by-file audit of the module; the code and tests in the merge request are written by Claude Code, with the affected test classes run locally and the whole suite run by the project pipeline. The maintainer reviews and merges.

Issue fork orchestra-3624691

Command icon Show commands

Start within a Git clone of the project using the version control instructions.

Or, if you do not have SSH keys set up on git.drupalcode.org:

Comments

mably created an issue. See original summary.

mably’s picture

Status: Active » Needs review

  • mably committed e1168188 on 1.x
    fix: #3624691 The redirect interaction never reaches its off-site...
mably’s picture

Status: Needs review » Fixed

Now that this issue is closed, review the contribution record.

As a contributor, attribute any organization that helped you, or if you volunteered your own time.

Maintainers, credit people who helped resolve this issue.