DEV: Require sso and sig query string params for sso_login
This commit is contained in:
parent
2502a3f780
commit
39b7e32848
|
@ -108,6 +108,9 @@ class SessionController < ApplicationController
|
|||
def sso_login
|
||||
raise Discourse::NotFound.new unless SiteSetting.enable_sso
|
||||
|
||||
params.require(:sso)
|
||||
params.require(:sig)
|
||||
|
||||
sso = DiscourseSingleSignOn.parse(request.query_string)
|
||||
if !sso.nonce_valid?
|
||||
if SiteSetting.verbose_sso_logging
|
||||
|
|
Loading…
Reference in New Issue