This repository was archived by the owner on Feb 25, 2019. It is now read-only.
Repository navigation
Security update
·
236 commits
to master
since this release
If you are running Anvil Connect 0.1.52 or earlier, please upgrade to 0.1.53. This release patches a security vulnerability.
Changes:
- Fix: unverified
redirect_uriredirect vulnerability (#216) - Fix: Improve
nvcommand behaviour and output - Fix: Improve standards-compliance with fragment and query string URLs
- Fix: Validate
redirect_urisproperly (#215) - Fix: Validate that
jwksandjwks_uriare not both used on clients (#98) - New: Support
noneresponse_type (#55)