Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Wrong encoding used for basic Authorization header #359

Open
mazocode opened this issue Jan 23, 2023 · 1 comment
Open

Wrong encoding used for basic Authorization header #359

mazocode opened this issue Jan 23, 2023 · 1 comment

Comments

@mazocode
Copy link

The header is generated by url encoding the username and password before base64 encoding. This is wrong and may result in authentication errors with special characters within username or credentials.

See requestTokens() and others in OpenIDConnectClient.php

@azmeuk
Copy link
Collaborator

azmeuk commented Mar 29, 2023

Hi. Thank you for your report.
Would you consider submitting a PR including a test demonstrating the authentication errors you are referring to?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants