7dd2b04343
no-issue the ssoOriginCheck exists to ensure that we only allow signin/signup to be called from the specified auth page, this is a very minor security feature in that it forces signins to go via the page you've designated. signout however does not need this protection as the call to signout completely bypasses any UI (this is the same for the call to /token) |
||
---|---|---|
.. | ||
common | ||
fs | ||
image | ||
members | ||
mobiledoc | ||
promise | ||
security | ||
social | ||
constants.js | ||
ghost-version.js | ||
request.js |