Tags: uuace/authn-server
Tags
Merge pull request keratin#23 from keratin/redis-optional Redis is optional
Merge pull request keratin#18 from keratin/metrics add: `GET /metrics` (authenticated)
verify Origin header instead of Referer the Origin header is already a dependency for CORS and was intended for this purpose: https://www.owasp.org/index.php/Cross-Site_Request_Forgery_(CSRF)_Prevention_Cheat_Sheet#Verifying_Same_Origin_with_Standard_Headers