Skip to content

Conversation

@dshanske
Copy link
Member

Started this with the goal of updating websignin to the latest version of the specification. It now supports PKCE, uses the code flow, and can use the metadata endpoint and therefore supports issuer verification for additional security.

While testing this, discovered that while all the PKCE tests passed, the system was not properly redirecting them, so since we still accept non PKCE flows, it was letting it through as if it wasn't there. Fixed that here.

Also changed the notice to show when PKCE isn't being used, as opposed to used.

@dshanske dshanske requested a review from pfefferle November 15, 2023 01:49
@dshanske dshanske removed the request for review from pfefferle November 30, 2023 23:00
@dshanske dshanske merged commit 7ba4fd2 into indieweb:trunk Nov 30, 2023
@dshanske dshanske deleted the websignin branch November 30, 2023 23:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant