Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
fix: stop sending state on the authorisation code token grant
This was added a long time ago as it was recommended by an early ‘mix-up mitigation’ draft. It is now no longer the recommended option as evidenced by the latest ‘oauth security topics’ BCP.
- Loading branch information