[OAUTH-WG] Security Bug | Unintended usage of "state" parameter can lead to Header Injection Attacks

2024-07-01 Thread Chaitanya Reddy
ter weeks of communication over the ticket, the engineer feels like they are not in disagreement with the spec and have requested me to discuss it further with your team and hence i am reaching out to you. Please let me know your thoughts about this. Regards, Chaitanya Reddy __

[OAUTH-WG] Re: Security Bug | Unintended usage of "state" parameter can lead to Header Injection Attacks

2024-07-01 Thread Chaitanya Reddy
lso have measures to sanitize the issue? My only point of asking this is i believe the authorization server should have also validated the state but they haven't. Regards, Chaitanya Reddy On Mon, Jul 1, 2024 at 6:33 PM Chaitanya Reddy < nchaitreddyutilit...@gmail.com> wrote: > Hi Neil an