GitHub の OAuth 認証には GET https://github.com/login/oauth/authorize に state というランダムな値をとる引数があり、こちらが送った値とResponseが一致するかで CSRF対策として使えることを知った
https://docs.github.com/en/developers/apps/authorizing-oauth-apps#web-application-flow
GitHub の OAuth 認証には GET https://github.com/login/oauth/authorize に state というランダムな値をとる引数があり、こちらが送った値とResponseが一致するかで CSRF対策として使えることを知った
https://docs.github.com/en/developers/apps/authorizing-oauth-apps#web-application-flow
senooken JP Social is a social network, courtesy of senooken. It runs on GNU social, version 2.0.2-beta0, available under the GNU Affero General Public License.
All senooken JP Social content and data are available under the Creative Commons Attribution 3.0 license.