Skip to content
This repository has been archived by the owner on Apr 7, 2020. It is now read-only.

Vulnerable to CSRF attack #36

Open
mattes opened this issue Apr 23, 2018 · 0 comments
Open

Vulnerable to CSRF attack #36

mattes opened this issue Apr 23, 2018 · 0 comments

Comments

@mattes
Copy link

mattes commented Apr 23, 2018

The implementation uses the the redirect_url as state param. The returned state is never checked anyway. state should be a random nonce to prevent CSRF attacks.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant