adorsys / adorsys/oauth2-pkce

State handling

未关闭
#10 0 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看
主要语言
Java
星标
12
派生
5
PR 合并指标
30 天内没有已合并 PR

描述

From my understanding, in order to protect against CSRF attacks, state field should be kept on the server in session or something for later comparison but at the moment it is being sent back in response cookie.

https://auth0.com/docs/protocols/oauth2/oauth-state

贡献指南

这个仓库没有索引到贡献指南

评估

这个 Issue 还没有评估数据。

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。