Skip to content

When storing PKCE code_verifier in session cookie, must it be encrypted, or is it enough for it to be signed? #455

Unanswered
lpsinger asked this question in Q&A
Discussion options

You must be logged in to vote

Replies: 1 comment 1 reply

Comment options

You must be logged in to vote
1 reply
@panva
Comment options

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
3 participants