]> git.ipfire.org Git - thirdparty/dovecot/core.git/commitdiff
lib-oauth2: Do not send client_id & client_secret as POST parameters when doing intro...
authorAki Tuomi <aki.tuomi@open-xchange.com>
Fri, 12 May 2023 05:59:50 +0000 (08:59 +0300)
committerAki Tuomi <aki.tuomi@open-xchange.com>
Mon, 29 May 2023 07:21:58 +0000 (10:21 +0300)
src/lib-oauth2/oauth2-request.c

index 8fbd6d70707288ccea2603b4679f588ead4ee332..3d1ba1d206244125beb7e5db0fd6de865536fbd5 100644 (file)
@@ -288,10 +288,6 @@ oauth2_introspection_start(const struct oauth2_settings *set,
                payload = str_new(p, strlen(input->token)+6);
                str_append(payload, "token=");
                http_url_escape_param(payload, input->token);
-               str_append(payload, "&client_id=");
-               http_url_escape_param(payload, set->client_id);
-               str_append(payload, "&client_secret=");
-               http_url_escape_param(payload, set->client_secret);
                url = set->introspection_url;
                method = "POST";
                break;