KEYCLOAK-6700 Financial API Read and Write API Security Profile : state

hash value (s_hash) to protect state parameter
This commit is contained in:
Takashi Norimatsu 2018-03-12 11:13:56 +09:00 committed by Marek Posolda
parent e72756d01a
commit 5b1e65c23e

View file

@ -221,7 +221,7 @@ public class OIDCLoginProtocol implements LoginProtocol {
// Financial API - Part 2: Read and Write API Security Profile
// http://openid.net/specs/openid-financial-api-part-2.html#authorization-server
if (state != null)
if (state != null && !state.isEmpty())
responseBuilder.generateStateHash(state);
}