keycloak-scim/services/src/main
Florian Ritterhoff 65480cb5a1 Prevent security flaw using passwordless authentication
If you register without an password or delete your last token your account can be hijacked. This is can be done by simply trying to login in that moment where the account is without a token. You get the "normal" registration dialog and can capture the complete account.
2021-08-03 10:49:45 -03:00
..
java/org/keycloak Prevent security flaw using passwordless authentication 2021-08-03 10:49:45 -03:00
resources KEYCLOAK-7724 User Profile default validations 2021-07-29 08:42:37 +02:00