Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Fix OAuth2 code verifier too short (#1793) #1809

Merged

Conversation

pietrygamat
Copy link
Contributor

@pietrygamat pietrygamat commented Mar 14, 2024

Description

As per RFC 7636: Proof Key for Code Exchange we should expect code verifier to be at least 43 characters after URL encode. Current implementation gives only 32.

Contribution Checklist:

  • The pull request only addresses one issue or adds one feature.
  • The pull request does not introduce any breaking changes
  • I have added screenshots or gifs to help explain the change if applicable.
  • I have read the contribution guidelines.
  • Create an issue and link to the pull request.

Fixes #1793

@pietrygamat pietrygamat force-pushed the bugfix/code_verifier_too_short branch from f9a3b84 to 22b36a7 Compare March 19, 2024 08:31
@helloanoop helloanoop merged commit ae3c76a into usebruno:main Mar 22, 2024
0 of 3 checks passed
@helloanoop
Copy link
Contributor

Merged.

Thank you @pietrygamat !

@pietrygamat pietrygamat deleted the bugfix/code_verifier_too_short branch March 22, 2024 13:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

BUG: OAuth2: code verifier too short
2 participants