- CSRF: store OAuth state in Secure/HttpOnly cookie, validate on callback - Cache-Control: add no-cache, no-store headers to all responses - Sensitive info: callback errors now 302 redirect instead of returning HTML - Logging: remove realmId and sanitize error logs to prevent QBO data leaks |
||
|---|---|---|
| .. | ||
| index.ts | ||