Skip to content

Breaks Claude.AI login #510

Description

@sirati

on claude.ai email magic links, the addon removes the trailing == (probably of the base64 encoding) which makes it impossible to login to claude

Activity

  1. AGlezB commented on Apr 24, 2026

    @AGlezB

    Confirmed. I got the solution from to disable ClearURLs from this Reddit post. Apparently it isn't something new because the post is 2 years old.

  2. firegurafiku commented on Apr 27, 2026

    @firegurafiku

    Just encountered this issue too.

    Apparently, the problem was caused by the trailing ==. Unfortunately, according to RFC3986, they're completely legal in URI fragments, so it's definitely a bug.

    The relevant part of the URI grammar from the RFC:

    URI         = scheme ":" hier-part [ "?" query ] [ "#" fragment ]
    fragment    = *( pchar / "/" / "?" )
    pchar       = unreserved / pct-encoded / sub-delims / ":" / "@"
    pct-encoded = "%" HEXDIG HEXDIG
    sub-delims  = "!" / "$" / "&" / "'" / "(" / ")" / "*" / "+" / "," / ";" / "="
    
  3. Arszilla commented on Apr 27, 2026

    @Arszilla

    Same here - just noticed the = at the end of the URL was missing - which was giving me more headache than I ever imagined it would.

    The solution would be either:

    • Whitelist Claude's login URL from ClearURLs
    • Give users the ability to whitelist certain domains/URLs
  4. sirati commented on Apr 27, 2026

    @sirati
    Author
    • Give users the ability to whitelist certain domains/URLs

    I had opened this issue for that: #509

  5. rbalogic commented on May 20, 2026

    @rbalogic

    I dug into this and the claude.ai login break looks like a real bug in ClearURLs' fragment handling, not just a site-specific incompatibility.

    The likely problem is that fragment values are being parsed and reconstructed in a lossy way. In particular, fragments containing legal payloads like base64-style tokens with trailing = / == can be rewritten incorrectly, which would explain why Claude magic links stop working.

    So I think there are two separate follow-ups here:

    1. A bugfix PR to preserve fragment content correctly and add regression coverage for cases like #token==.
    2. A separate feature PR to add a per-site disable/whitelist option, so users have an escape hatch when a site breaks before a fix is released.

    I’m planning to handle these as two PRs rather than one combined change, so the correctness fix can be reviewed and shipped independently of the UI/feature work.

  6. rbalogic commented on May 21, 2026

    @rbalogic

    I opened a PR for the Claude-related breakage: #514

    The fix is scoped to fragment preservation. The current fragment parser was reconstructing hash payloads in a lossy way when they contained trailing = / == or additional = characters, which can break opaque tokens like the ones used in Claude magic links.

    This PR updates fragment parsing so it:

    • splits only on the first =
    • preserves everything after that verbatim
    • keeps empty fragment values intact

    That means cases like these now round-trip correctly:

    • #token=
    • #token==
    • #state=abc==
    • #foo=bar=baz

    I kept this separate from the proposed per-site disable feature so the correctness fix can be reviewed and shipped independently.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions