This change ensures that we always store and then check the contents of the OAuth `state` argument against a session-stored CSRF token. Fixes https://www.pivotaltracker.com/story/show/135803615 |
||
|---|---|---|
| .. | ||
| css | ||
| directives | ||
| img | ||
| js | ||
| lib | ||
| partials | ||
| standalonelib | ||
| tutorial | ||
| 502.html | ||