Make redirect URI a required parameter for auth code flow#188
Merged
jhendrixMSFT merged 2 commits intodevfrom Mar 4, 2021
Merged
Make redirect URI a required parameter for auth code flow#188jhendrixMSFT merged 2 commits intodevfrom
jhendrixMSFT merged 2 commits intodevfrom
Conversation
Don't hard-code the nativeclient redirect URI. Make the auth code a parameter for the public client (the same was already done for confidential client).
Contributor
Author
|
Change is based on the discussion here. |
abhidnya13
approved these changes
Mar 4, 2021
Contributor
abhidnya13
left a comment
There was a problem hiding this comment.
LGTM,
I think we should also mention may be in the comments/reference docs that this RedirectUri has to be the same as the one used in the first leg of this flow.
|
Kudos, SonarCloud Quality Gate passed!
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Don't hard-code the nativeclient redirect URI.
Make the auth code a parameter for the public client (the same was
already done for confidential client).