ContainerImage.Pinniped/internal/oidc/callback
Andrew Keesler b21f0035d7 callback_handler.go: Get upstream name from state instead of path
Also use ConstantTimeCompare() to compare CSRF tokens to prevent
leaking any information in how quickly we reject bad tokens.

Signed-off-by: Ryan Richard <richardry@vmware.com>
2020-11-20 13:33:08 -08:00
..
callback_handler_test.go callback_handler.go: Get upstream name from state instead of path 2020-11-20 13:33:08 -08:00
callback_handler.go callback_handler.go: Get upstream name from state instead of path 2020-11-20 13:33:08 -08:00