Open
Description
@agrobbin @sferik Could you review this, if you still have an interest in the issue?
#70 was merged without a spec, so I added specs to make my intention clear. If redirect_uri
is given in token_params
, it should be honored. If not, query parameters added by the OAuth2 provider in a callback should be stripped off from the redirect_uri value to be posted to the token endpoint, to avoid redirect_uri mismatch.
Originally posted by @knu in #100 (comment)
Metadata
Metadata
Assignees
Labels
No labels