Skip to content

CSRF name changed in v2.x #3801

Closed Answered by terev
rubanraj-r asked this question in Q&A
Discussion options

You must be logged in to vote

The random number is actually a hash of the oauth client's id. Seems to be so that login session csrf tokens are isolated based on the oauth client. In turn this allows concurrent login sessions for different oauth clients to succeed.

Replies: 2 comments

Comment options

You must be logged in to vote
0 replies
Answer selected by rubanraj-r
Comment options

You must be logged in to vote
0 replies
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants