Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

oidc: shouldn't the state be random? #49

Open
bbigras opened this issue Nov 25, 2019 · 2 comments
Open

oidc: shouldn't the state be random? #49

bbigras opened this issue Nov 25, 2019 · 2 comments

Comments

@bbigras
Copy link

bbigras commented Nov 25, 2019

Shouldn't the state be random (or maybe derived from the session) to protect against attacks?

https://auth0.com/docs/protocols/oauth2/oauth-state

@OKinane
Copy link

OKinane commented Jan 31, 2024

Hello @Luzifer, any comment on this issue?

@Luzifer Luzifer added this to the Version 1.x - Rewrite milestone Feb 6, 2024
@Luzifer
Copy link
Owner

Luzifer commented Feb 6, 2024

With the current structure of the repo / providers it's not possible as the provider to fulfill the login is chosen from the state. I've added this to the v1.x plan: #87

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants