-
Notifications
You must be signed in to change notification settings - Fork 162
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Enforce redirect_uri by allowed prefix #1
Comments
The existence of |
The existence is enforced, but really the value should be checked to ensure that the I'm thinking of adding an |
Apologies, I didn't properly see that |
+1, going to do this manually for now but the module should definitely require it |
+1 just stumbled on this. Perhaps it could be useful to also do something like what's described in the "User agent flow" section of this blog post: http://www.sociallipstick.com/?p=239
Basically, if the redirect_uri is present and matches, send an access token directly. |
Check to make sure that any redirect_uri that is passed in is allowed for that particular client_id.
The text was updated successfully, but these errors were encountered: