3 ms·
You could just add some kind of hash based on the redirect url and check that, to ensure that it can't be altered.
by tikumo 8y ago
You could just add some kind of hash based on the redirect url and check that, to ensure that it can't be altered.
- xxs 8y agoFor this you need some pepper (i.e. a secret) to prevent doctoring. The better option is an encrypted blob containing all relevant data and a timing component. Of course those thing do require effort. It makes it opaque for everyone but the server handling the redirect.