Skip to content

Commit

Permalink
Merge pull request #428 from rushilsrivastava/master
Browse files Browse the repository at this point in the history
🐛 Clear state from session in OAuth2
  • Loading branch information
lepture authored Feb 28, 2022
2 parents 1089d54 + b6eb5eb commit 48b1895
Show file tree
Hide file tree
Showing 3 changed files with 3 additions and 0 deletions.
1 change: 1 addition & 0 deletions authlib/integrations/django_client/apps.py
Original file line number Diff line number Diff line change
Expand Up @@ -76,6 +76,7 @@ def authorize_access_token(self, request, **kwargs):
}

state_data = self.framework.get_state_data(request.session, params.get('state'))
self.framework.clear_state_data(request.session, params.get('state'))
params = self._format_state_params(state_data, params)
token = self.fetch_access_token(**params, **kwargs)

Expand Down
1 change: 1 addition & 0 deletions authlib/integrations/flask_client/apps.py
Original file line number Diff line number Diff line change
Expand Up @@ -98,6 +98,7 @@ def authorize_access_token(self, **kwargs):
}

state_data = self.framework.get_state_data(session, params.get('state'))
self.framework.clear_state_data(session, params.get('state'))
params = self._format_state_params(state_data, params)
token = self.fetch_access_token(**params, **kwargs)
self.token = token
Expand Down
1 change: 1 addition & 0 deletions authlib/integrations/starlette_client/apps.py
Original file line number Diff line number Diff line change
Expand Up @@ -70,6 +70,7 @@ async def authorize_access_token(self, request, **kwargs):
session = request.session

state_data = await self.framework.get_state_data(session, params.get('state'))
await self.framework.clear_state_data(session, params.get('state'))
params = self._format_state_params(state_data, params)
token = await self.fetch_access_token(**params, **kwargs)

Expand Down

0 comments on commit 48b1895

Please sign in to comment.