fix(admin-api): omit clientSecret from getConfig response for security & add OIDC scope.
This commit is contained in:
@@ -111,6 +111,8 @@ class AuthController
|
||||
$cfg['oidc']['clientSecret']
|
||||
);
|
||||
$oidc->setRedirectURL($cfg['oidc']['redirectUri']);
|
||||
$oidc->addScope(['openid','profile','email']);
|
||||
|
||||
|
||||
if ($oidcAction === 'callback') {
|
||||
try {
|
||||
|
||||
Reference in New Issue
Block a user