Fix OAuth2 error code when supplying invalid code

reject-browser-part-of-url
Maxime Besson 4 years ago
parent 5a8c20584b
commit 4841c7755e
  1. 2
      lemonldap-ng-portal/lib/Lemonldap/NG/Portal/Issuer/OpenIDConnect.pm

@ -1263,7 +1263,7 @@ sub _handleAuthorizationCodeGrant {
my $codeSession = $self->getAuthorizationCode($code);
unless ($codeSession) {
$self->logger->error("Unable to find OIDC session $code");
return $self->sendOIDCError( $req, 'invalid_request', 400 );
return $self->sendOIDCError( $req, 'invalid_grant', 400 );
}
$codeSession->remove();

Loading…
Cancel
Save