Exact-Match Validation Before Token Issuance
A small redirect bug, three services, and why startsWith is not a security check. Single sign-on flows usually end the same way: the user logs in, and the identity provider sends them back to the app that asked, along with a session. The URL they’re sent back to is often just a query parameter. In our case, nobody was checking… Continue reading Exact-Match Validation Before Token Issuance