changeset 5454:6970c73711c2

mod_http_oauth2: Reject duplicate redirect URIs in registration
author Kim Alvefur <zash@zash.se>
date Tue, 16 May 2023 21:04:31 +0200
parents 7dc429b7c3f3
children 80a81e7f3c4e
files mod_http_oauth2/mod_http_oauth2.lua
diffstat 1 files changed, 1 insertions(+), 1 deletions(-) [+]
line wrap: on
line diff
--- a/mod_http_oauth2/mod_http_oauth2.lua	Tue May 16 20:56:57 2023 +0200
+++ b/mod_http_oauth2/mod_http_oauth2.lua	Tue May 16 21:04:31 2023 +0200
@@ -754,7 +754,7 @@
 		"redirect_uris";
 	};
 	properties = {
-		redirect_uris = { type = "array"; minItems = 1; items = { type = "string"; format = "uri" } };
+		redirect_uris = { type = "array"; minItems = 1; uniqueItems = true; items = { type = "string"; format = "uri" } };
 		token_endpoint_auth_method = {
 			type = "string";
 			enum = { "none"; "client_secret_post"; "client_secret_basic" };