bunnings trade site in firefox always runs through this login box thats dumped full of json for some reason. what crimes are going on

Looks like it just sets the redirectUri?

{"auth":{"operation":"trade_login","redirectUri":"https://trade.bunnings.com.au/sign-in"}}

I had to scratch that itch. this site has.... vibes
A lot of questions being asked about the "intranet" subdomain
I love that this host just like, has directory listing enabled as well
I also love that companies just have their uat shit hanging out on the internet
what if we put our MCP server uri into an openid scope?

"you shouldn't be poking around at this stuff"

hey! it told me to!

this ones just... weird.

anyway, thats how you can find a bunch of interesting things to explore by just googling around for inurl:bunnings / domain:bunnings.com.au

why bunnings? not sure, got distracted.

@xssfox thanks, I hate it
@xssfox if they don't fuck it all up then they'd be left to just seeing other people doing it!
@xssfox because despite the name, the testers doing user acceptance are not internal users, they're remote contractors.
@xssfox You are giving me flashbacks to a project I was on in the 2000s which I might rant at you about if prompted should we ever be in direct ranting range.
@xssfox lol oracle cloud