Skip to content

feat: add state parameter to get_auth_link - #120

Closed
hsluoyz wants to merge 1 commit into
masterfrom
auth-link-state
Closed

hsluoyz wants to merge 1 commit into
masterfrom
auth-link-state

Conversation

@hsluoyz

@hsluoyz hsluoyz commented Oct 3, 2026

Copy link
Copy Markdown
Member

Fix: #115

get_auth_link always used the application name as state, so backends had no way to pass a random per-login value and check it on the callback for CSRF protection. This adds an optional state argument (sync and async; default unchanged) and documents in the README how to use it, and that casdoor-js-sdk already checks state in the browser before calling signinPath.

@hsluoyz hsluoyz closed this Oct 3, 2026
@hsluoyz
hsluoyz deleted the auth-link-state branch October 3, 2026 15:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

State

1 participant