|
|
|
|
|
by mohon
968 days ago
|
|
Good explanation. Quick follow up, so to resolve this issue, what I have in mind are : 1. Make sure the redirect url is a valid harvestapp.com (more checks on state) 2. Encrypt the state since the start of the request, so then they can double check the state hasn't been forged by decrypt and compare Is there any option beside those? |
|