Homec4science

Fix an OAuthServer issue where an attacker could make a link function over HTTP…

Authored by epriestley <git@epriestley.com> on Feb 20 2013, 01:09.

Description

Fix an OAuthServer issue where an attacker could make a link function over HTTP when it should be HTTPS-only

Summary:
Two behavioral changes:

iiam

Test Plan: This has good coverage already; added some tests for the new cases.

Reviewers: vrana

Reviewed By: vrana

CC: cbg, aran, btrahan

Differential Revision: https://secure.phabricator.com/D5022

Details

Committed
epriestley <git@epriestley.com>Feb 20 2013, 01:09
Pushed
aubortJan 31 2017, 17:16
Parents
rPH2191e99b49a2: Delete unused variable
Branches
Unknown
Tags
Unknown

Event Timeline

epriestley <git@epriestley.com> committed rPH41b9752ba8a3: Fix an OAuthServer issue where an attacker could make a link function over HTTP… (authored by epriestley <git@epriestley.com>).Feb 20 2013, 01:09