(no title)
mohon | 2 years ago
1. Make sure the redirect url is a valid harvestapp.com (more checks on state)
2. Encrypt the state since the start of the request, so then they can double check the state hasn't been forged by decrypt and compare
Is there any option beside those?
nurple|2 years ago
bavell|2 years ago