[medium] oauth-patterns: OAuth flow without PKCE #40
Reference in New Issue
Block a user
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
medium Finding
Scanner: oauth-patterns
Severity: medium
Rule: oauth-missing-pkce
Description
Authorization code flow should use PKCE (code_challenge/code_verifier) for public clients.
Location
File:
compliance-dashboard/src/infrastructure/auth.rs(line 151)Code
Fingerprint:
4b12b424f24d0dbcefb77999b6f10aa56c236b9265c99e77a8dc189a487ed5dbGenerated by compliance-scanner
Labels: severity:medium, scanner:oauth-patterns, compliance-scanner