You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
In OAuth2 for the implicit grant you have to check the Redirect URL, because in this case this is the only way to authorize the client identify. I checked and your application not check it, and I can use any redirect URL if I know the client key.
If you agree it, I can create a pull request for fill the security hole.
The text was updated successfully, but these errors were encountered:
In OAuth2 for the implicit grant you have to check the Redirect URL, because in this case this is the only way to authorize the client identify. I checked and your application not check it, and I can use any redirect URL if I know the client key.
If you agree it, I can create a pull request for fill the security hole.
The text was updated successfully, but these errors were encountered: