Reviewed & tested by the community
Project:
OAuth Connector
Version:
7.x-1.x-dev
Component:
Code
Priority:
Critical
Category:
Bug report
Assigned:
Reporter:
Created:
31 Jul 2016 at 19:01 UTC
Updated:
25 Jan 2017 at 03:56 UTC
Jump to comment: Most recent
Comments
Comment #2
fortis commentedThe client implementation doesn't use state parameter to mitigate CSRF
Comment #3
fortis commentedComment #4
fortis commentedComment #5
fortis commentedComment #6
fortis commentedComment #7
somatick commentedHave tested the patch. This is an important addition which does not interfere with the authentication process.
http://www.twobotechnologies.com/blog/2014/02/importance-of-state-in-oau...