Add state parameter to CLI browser login flow for CSRF protection — CLI generates a random state, frontend passes it through, CLI verifies on callback. Also restrict cli_callback to http: scheme only. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| (auth)/login | ||
| (dashboard) | ||
| favicon.ico | ||
| pair/local | ||
| custom.css | ||
| globals.css | ||
| layout.tsx | ||
| page.tsx | ||