You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
carolyncole
changed the title
Updating omniauth to not allow for any token to be passed
Updating omniauth to not allow for old token to be passed
Jun 4, 2024
Expected Behavior
Only a CAS-authenticated user with a vaild CSRF token should be allow access into orcid staging and prod.
Current Behavior
Currently, a user with any CSRF token may be able to authenticate into orcid.
Implementation notes
These are links for potential refactors to the code that would add extra security for authentication into orcid for users through CAS.
See: #151 See line
Acceptance Criteria
The text was updated successfully, but these errors were encountered: