Files
endurain/backend
João Vitória Silva 4727732053 Enforce OAuth 2.1 PKCE, unify token handling, and add MFA lockout
This update enforces PKCE for all OAuth flows, removes legacy cookie-based state, and unifies token handling for both web and mobile clients to comply with OAuth 2.1. It introduces a progressive lockout mechanism for MFA to prevent brute-force attacks, updates CSRF middleware to require only the header, and ensures refresh tokens are set as httpOnly cookies with SameSite=Strict. The frontend is updated to restore tokens on app initialization and handle SSO token exchange failures. Various backend endpoints and utilities are refactored for clarity, security, and consistency.
2025-12-17 17:05:04 +00:00
..
2025-12-15 12:50:35 +00:00