Skip to content
This repository has been archived by the owner on Dec 20, 2020. It is now read-only.

PBAL: Does not validate nonce and state on OAuth flow #5

Open
koolin opened this issue Sep 12, 2017 · 0 comments
Open

PBAL: Does not validate nonce and state on OAuth flow #5

koolin opened this issue Sep 12, 2017 · 0 comments

Comments

@koolin
Copy link
Contributor

koolin commented Sep 12, 2017

PBAL implementation on authorize does not set and cache nonce and state to unique values. On receipt of iframe hash does not validate state and does not inspect id token or access token for nonce.

@koolin koolin changed the title PBAL does not validate nonce and state on OAuth flow PBAL: Does not validate nonce and state on OAuth flow Sep 12, 2017
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant