KnowledgeHub
Questions
Tags
Users
Search
Alex Rivera
|
Logout
Edit Question
Title
Body
I am successfully able to authenticate Facebook and Google accounts using my Oauth2 servlets. I am using state with a timer and a session cookie to try to verify that it is indeed a legitimate Oauth callback. Is there any benefit if I also examine the HTTP Referer header to ensure that I was redirected from the provider's OAuth page? If no benefit, could there be a problem if I also examine the HTTP Referer field?
Tags (comma-separated)
Save Edits
Cancel