Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We鈥檒l occasionally send you account related emails.

Already on GitHub? Sign in to your account

Verify state before using errors received from provider #144

Merged
merged 1 commit into from Nov 2, 2021
Merged

Verify state before using errors received from provider #144

merged 1 commit into from Nov 2, 2021

Commits on Nov 2, 2021

  1. Verify state before using errors received from provider

    This avoids content spoofing attacks by crafting a URL with malicious
    messages, because the `state` param is only present in the session after
    a valid OAuth2 authentication flow.
    Markus Koller committed Nov 2, 2021
    Copy the full SHA
    98553d7 View commit details
    Browse the repository at this point in the history