Skip to content

Missing CSRF protection #161

@xi

Description

@xi

Issue Description

OAuth 2.1 requires that there is CSRF protection by using state, nonce, code_challenge, or a combination of those. It recommends to use at least code_challenge.

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions