Skip to content

Deploy RC62.1 into int#2362

Merged
jgsmith-usds merged 2 commits intostages/intfrom
stages/rc-2018-07-20-patch-1
Jul 23, 2018
Merged

Deploy RC62.1 into int#2362
jgsmith-usds merged 2 commits intostages/intfrom
stages/rc-2018-07-20-patch-1

Conversation

@jgsmith-usds
Copy link
Contributor

This adds two fixes to the 20 July 2018 RC:

  1. Fix 500 errors on bad personal key
  2. Match host on redirect URIs

stevegsa and others added 2 commits July 23, 2018 09:48
**Why**:
If we only test that the redirect starts with a valid
string, then we are open to some SPs having redirects
with incorrect hosts redirecting users to the wrong server.

**How**:
We parse the redirect URI and compare significant parts.
@jgsmith-usds jgsmith-usds changed the title Merge RC62.1 into int Deploy RC62.1 into int Jul 23, 2018
Copy link
Contributor

@monfresh monfresh left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants