是 Hono 的认证中间件。在 0.8.6 版本之前,内置的社交登录提供者即使双方都缺失 值,也会接受 OAuth 回调,导致防 CSRF 检查通过了一个并非来自真实登录尝试的回调。在默认使用场景下,这使得基于 的 CSRF 保护失效。0.8.6 版本已提供补丁修复此问题。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| honojs | @hono/oauth-providers | < 0.8.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet