Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Should compare sub in access_token and id_token to verify that it is from the same user to prevent that a user can impersonate another user. #124

Open
dniel opened this issue Sep 18, 2019 · 0 comments
Assignees
Labels
bug Something isn't working

Comments

@dniel
Copy link
Owner

dniel commented Sep 18, 2019

verify both tokens, and check that the sub fields is the same in both.

@dniel dniel added the bug Something isn't working label Sep 18, 2019
@dniel dniel self-assigned this Sep 18, 2019
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working
Projects
None yet
Development

No branches or pull requests

1 participant