max-mapper / max-mapper/github-oauth
`state` parameter is useless as-implemented
Open
Nobody has claimed this yet.
- Dominant language
- JavaScript
- Stars
- 71
- Forks
- 20
- PR merge metrics
- No merged PRs in 30d
Description
- The
statevalue is generated on initialization and re-used for all requests, so a potential attacker can obtain the value. It should be unique per-request and un-guessable. - The callback does not verify the
statepassed back from GitHub.
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Trace where the state value is initialized and reused for requests, then follow the GitHub callback handling described in the issue. The work is done when each request has a unique, unguessable state value and the callback verifies the returned state.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- github, javascript, node.js
- Domain
- authentication, security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100