From 865c3829869bfebb146aac7e2981234d04e1ac64 Mon Sep 17 00:00:00 2001 From: Radoslav Dimitrov Date: Sat, 26 Sep 2026 23:28:42 +0300 Subject: [PATCH] Fix spelling flagged by codespell The Spellcheck workflow runs only on pull requests, and the advisory fork that delivered the browser-binding fix had no CI, so this comment reached main unchecked and now fails the check on the v0.51.3 release PR. Co-Authored-By: Claude Fable 5.1 --- pkg/authserver/server/handlers/browser_binding.go | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/pkg/authserver/server/handlers/browser_binding.go b/pkg/authserver/server/handlers/browser_binding.go index 6730e859d0..815b32e155 100644 --- a/pkg/authserver/server/handlers/browser_binding.go +++ b/pkg/authserver/server/handlers/browser_binding.go @@ -126,7 +126,7 @@ func hashBrowserBindingSecret(value string) string { // browserBindingSecure reports whether the browser-facing authorize URL is // served over https, which decides both the Secure attribute and the "__Host-" // prefix. Config validation guarantees the URL parses with an http or https -// scheme; an unparseable value falls back to the plain-http shape, which every +// scheme; an unparsable value falls back to the plain-http shape, which every // browser accepts. func (h *Handler) browserBindingSecure() bool { u, err := url.Parse(h.config.GetAuthorizationEndpointBaseURL())