Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Fix: OAuth2 Access Token request is sent as GET #1796

Closed

Conversation

pietrygamat
Copy link
Contributor

@pietrygamat pietrygamat commented Mar 14, 2024

Description

The client MUST use the HTTP "POST" method when making access token requests.

Contribution Checklist:

  • The pull request only addresses one issue or adds one feature.
  • The pull request does not introduce any breaking changes
  • I have added screenshots or gifs to help explain the change if applicable.
  • I have read the contribution guidelines.
  • Create an issue and link to the pull request.

Fixes #1795

@pietrygamat pietrygamat deleted the only-post-access-token branch March 14, 2024 08:20
@francoischaix-circeo
Copy link

The POST request is also valid for every flow. however this change only does it for authorization flow.

Copy link

@francoischaix-circeo francoischaix-circeo left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This applies the request method only to the authorization flow. But other flows are also requred to be sent as POST in every case. this will not fix the client_credentials and password flow

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

BUG: OAuth2: Access Token request is sent as GET
2 participants