Skip to content

fix: Return status 403 for invalid uaa oauth code #4781

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 1 commit into from
Apr 10, 2025

Conversation

apburnes
Copy link
Contributor

@apburnes apburnes commented Apr 8, 2025

Closes https://github.com/cloud-gov/private/issues/2385

Changes proposed in this pull request:

  • Updates OAuth UAA strategy to return a 403 with invalid token.

security considerations

Fixes invalid oauth toke error response to 403 from 500

@apburnes apburnes force-pushed the fix-auth-callback-500-error branch from 31d0681 to e14ab5a Compare April 8, 2025 20:21
@apburnes apburnes force-pushed the fix-auth-callback-500-error branch from e14ab5a to 50f2f53 Compare April 8, 2025 21:01
@apburnes apburnes requested a review from a team April 8, 2025 22:00
@cloud-gov-pages-operations
Copy link
Contributor

🤖 This is an automated code coverage report

Total coverage (lines): 34.04%
Coverage diff: 0% 📈

@apburnes apburnes merged commit 185e83c into main Apr 10, 2025
8 checks passed
@apburnes apburnes deleted the fix-auth-callback-500-error branch April 10, 2025 15:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants