Page MenuHomePhabricator

Remove "supportsStateParameter()" from generic OAuth2 code
ClosedPublic

Authored by epriestley on Feb 23 2014, 11:23 PM.
Tags
None
Referenced Files
F19508734: D8319.id.diff
Sat, Jan 10, 9:30 AM
F19507623: D8319.id.diff
Fri, Jan 9, 10:20 PM
F19303667: D8319.id19784.diff
Wed, Dec 24, 4:16 AM
F19296612: D8319.id.diff
Tue, Dec 23, 12:13 PM
F19072442: D8319.id.diff
Nov 30 2025, 10:36 PM
F19059202: D8319.diff
Nov 29 2025, 4:48 AM
F18905173: D8319.id.diff
Nov 8 2025, 1:10 PM
F18843511: D8319.id.diff
Oct 28 2025, 10:48 PM
Subscribers

Details

Summary

Depends on D8318. All providers must support this, or they can't be implemented securely. This is based on a very old reading of the GitHub instructions or something like that which didn't mention "state", but the provider supports it.

This has no impact at runtime because no provider has ever returned false from this method, nor would we ever implement a provider that did.

Test Plan

Grepped for callsites.

Diff Detail

Lint
Lint Skipped
Unit
Tests Skipped