CommentFileSizeAuthor
oauth_connector-156551-12.patch1.28 KBfortis

Comments

fortis created an issue. See original summary.

fortis’s picture

The client implementation doesn't use state parameter to mitigate CSRF

fortis’s picture

Status: Active » Needs review
fortis’s picture

Title: Use state parameter » use state parameter to mitigate CSRF
fortis’s picture

Title: use state parameter to mitigate CSRF » Use state parameter to mitigate CSRF
fortis’s picture

Priority: Normal » Critical
somatick’s picture

Status: Needs review » Reviewed & tested by the community

Have tested the patch. This is an important addition which does not interfere with the authentication process.
http://www.twobotechnologies.com/blog/2014/02/importance-of-state-in-oau...