•  
      request #9408 Prevent mix-up attacks with OpenID Connect
    Infos
    #9408
    Thomas Gerbet (tgerbet)
    2016-08-24 12:19
    2016-08-18 18:38
    9682
    Details
    Prevent mix-up attacks with OpenID Connect
    It is a best practice to add the support of the nonce parameter in the authentication flow to prevent mix-up attacks [1].
    Also, it could improve the number of providers we can use with the plugin since some of them like France Connect require the use of a nonce.

    [1] https://openid.net/2016/07/16/preventing-mix-up-attacks-with-openid-connect/
    Authentication & LDAP
    All
    Empty
    • [x] enhancement
    • [ ] internal improvement
    Empty
    Stage
    Empty
    Closed
    2016-08-24
    Attachments
    Empty
    References

    Follow-ups

    User avatar
    Integrated into Tuleap 8.18.99.15

    • Status changed from Under review to Closed
    • Connected artifacts
    • Close date set to 2016-08-24