Address PR review feedback for OIDC login
- Remove sensitive nonce values from error messages to prevent logging leaks - Guard ticker intervals against non-positive durations in SAML domain verifier and garbage collector to prevent panics - Require both client ID and client secret for Google/Microsoft OIDC providers to be marked as enabled - Replace http.DefaultClient with kit/httpclient for JWKS fetching to ensure proper timeouts - Fix eslint indentation in SignInPage OIDC button click handler Signed-off-by: Bryan Frimin <bryan@getprobo.com>
This commit is contained in:
@@ -71,6 +71,10 @@ func (gc *GarbageCollector) Run(ctx context.Context) error {
|
||||
gc.logger.ErrorCtx(ctx, "cannot run initial cleanup", log.Error(err))
|
||||
}
|
||||
|
||||
if gc.interval <= 0 {
|
||||
return fmt.Errorf("cannot run SAML garbage collector: interval must be greater than zero")
|
||||
}
|
||||
|
||||
ticker := time.NewTicker(gc.interval)
|
||||
defer ticker.Stop()
|
||||
|
||||
|
||||
Reference in New Issue
Block a user