Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

sec #13

Open
breatoz opened this issue May 16, 2016 · 2 comments
Open

sec #13

breatoz opened this issue May 16, 2016 · 2 comments

Comments

@breatoz
Copy link

breatoz commented May 16, 2016

sec

@iignatov
Copy link
Owner

I don't use this library (or PHP) anymore, so I have no plans to update it, but I could review/merge a PR.

@breatoz breatoz changed the title Openid.php has no validation on endpoint, identity, or claimed_id allowing forged requests sec May 21, 2016
@breatoz
Copy link
Author

breatoz commented May 21, 2016

I might update it shortly, been suddely swamped with other things -- everyone has been patched with something silly for now -- could of caused like $2m+ in damage (from someone stealing from users they login with) lol.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants