Files
endurain/docs
João Vitória Silva fd7542c0cf Add PKCE and server-side OAuth state for mobile SSO
Implements database-backed OAuth state management to support secure PKCE flows for mobile SSO. Adds new models, CRUD, and scheduled cleanup for OAuth state, updates identity provider login and callback flows to use server-side state, and introduces a token exchange endpoint for mobile clients. Updates session and rate limiting logic, and maintains backward compatibility for web clients using cookie-based state.
2025-12-16 14:02:31 +00:00
..
2024-11-15 21:04:52 +00:00