-
Notifications
You must be signed in to change notification settings - Fork 85
Open
Description
Hi Scott, firstly thanks for this awesome post on Legacy ASP.NET & PKCE!
In that article you mention:
// remember code verifier in cookie (adapted from OWIN nonce cookie)I'm curious why the cookie's key is somewhat stateful/dynamic..?
The problem I'm seeing is when the user refreshes, it creates new nonce & cv cookies, leaving the old ones orphaned. This could eventually cause the request header to grow too big.
Do you see any issue with changing this cookie key to something constant like OpenIdConnect.cv.foo?
Metadata
Metadata
Assignees
Labels
No labels