b21f0035d7
Also use ConstantTimeCompare() to compare CSRF tokens to prevent leaking any information in how quickly we reject bad tokens. Signed-off-by: Ryan Richard <richardry@vmware.com> |
||
---|---|---|
.. | ||
auth | ||
callback | ||
csrftoken | ||
discovery | ||
jwks | ||
oidctestutil | ||
provider | ||
nullstorage_test.go | ||
nullstorage.go | ||
oidc.go |