Skip to content

random `state` for openIDConnect

Pavlo Mashliakovskiy requested to merge fix/openIDConnectRandomState into master
  • during redirection to provider auth endpoint state parameter now filled randomly to prevent request forgery and stored in global cache;
  • during auth handshake state is compared with initial one (retrieved from global cache by cookie OIDC_SESSID_COOKIE value)

Merge request reports

Loading