Skip to content
This repository was archived by the owner on Jul 24, 2023. It is now read-only.

Commit d181a8a

Browse files
authored
Merge pull request #121 from faberge-eggs/SSRF-idref-fix
Avoid SSRF for claimed_id request
2 parents 6182dc4 + 8a4c31a commit d181a8a

1 file changed

Lines changed: 1 addition & 1 deletion

File tree

lib/openid/consumer/idres.rb

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -72,9 +72,9 @@ def signed_fields
7272
def id_res
7373
check_for_fields
7474
verify_return_to
75-
verify_discovery_results
7675
check_signature
7776
check_nonce
77+
verify_discovery_results
7878
end
7979

8080
def server_url

0 commit comments

Comments
 (0)