-
-
Notifications
You must be signed in to change notification settings - Fork 58
An option to require PKCE parameters #179
Copy link
Copy link
Open
Labels
compliance 📜OAuth 2.0 standard complianceOAuth 2.0 standard compliancedocumentation 📑Improvements or additions to documentationImprovements or additions to documentationsecurity ❗Address a security issueAddress a security issue
Metadata
Metadata
Assignees
Labels
compliance 📜OAuth 2.0 standard complianceOAuth 2.0 standard compliancedocumentation 📑Improvements or additions to documentationImprovements or additions to documentationsecurity ❗Address a security issueAddress a security issue
It seems it's fully optional right now:
node-oauth2-server/lib/grant-types/authorization-code-grant-type.js
Lines 122 to 144 in c993eb5
Could be great if there's an option to force it. Of course one can block the request manually by checking the query, though.