Please sign in to comment.
[oauth] Automatic management of state parameter
Ported from https://github.com/securedimensions/QGIS-OAuth2-Plugin The Boundless Geo version of the plugin requests the state parameter to be provided by the user. We have changed that as we think that the user must not be responsible for providing that, as a duplication of a state parameter could lead to unintentional errors. The Testbed 13 version generates the state parameter automatically for each authorization request to the Authorization Server and checks the value from the redirect to ensure no CSRF attacks.
- Loading branch information
Showing with 346 additions and 196 deletions.
Oops, something went wrong.