Skip to content

fix(oidc): state might be used in session keys - #199

Merged
ArtificialOwl merged 1 commit into
masterfrom
fix/noid/oidc_state_in_session_key
Jun 16, 2026
Merged

fix(oidc): state might be used in session keys#199
ArtificialOwl merged 1 commit into
masterfrom
fix/noid/oidc_state_in_session_key

Conversation

@ArtificialOwl

Copy link
Copy Markdown
Member

There is a probability that value from param 'state' is used as key suffix

of course no AI

@ArtificialOwl
ArtificialOwl force-pushed the fix/noid/oidc_state_in_session_key branch from 2119b91 to 217a444 Compare June 16, 2026 10:19

@cristianscheid cristianscheid left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

looks good to me

Signed-off-by: Maxence Lange <maxence@artificial-owl.com>
@ArtificialOwl
ArtificialOwl force-pushed the fix/noid/oidc_state_in_session_key branch from 217a444 to af98e7a Compare June 16, 2026 13:06
@ArtificialOwl
ArtificialOwl merged commit a2e11f7 into master Jun 16, 2026
34 of 38 checks passed
@ArtificialOwl
ArtificialOwl deleted the fix/noid/oidc_state_in_session_key branch June 16, 2026 13:29
@ArtificialOwl

Copy link
Copy Markdown
Member Author

/backport to stable2.7

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants