Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

关于state的使用问题 #76

Closed
yourke opened this issue May 14, 2020 · 1 comment
Closed

关于state的使用问题 #76

yourke opened this issue May 14, 2020 · 1 comment

Comments

@yourke
Copy link

yourke commented May 14, 2020

生成的state参数,是不是要和当前session绑定,或者存到cookie中,才能避免CSRF攻击?
攻击者可以使用自己的第三方账号,授权拿到code和state,诱导受害者去点击触发回调请求,在不绑定session的情况下,回调接口中对state校验是可以通过的。
我理解的有问题么?

@yourke yourke closed this as completed May 14, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants
@yourke and others