diff --git a/packages/backend/src/index.ts b/packages/backend/src/index.ts index c745398..e2753de 100644 --- a/packages/backend/src/index.ts +++ b/packages/backend/src/index.ts @@ -15,6 +15,7 @@ const csrfCheck = new CsrfCheck(); const pkceCheckController = new PKCECheck(); const tokenCheck = new AccessTokenLeakController(); const ScopeDetectionController = new ScopeDetection(); +// const nonceCheckController = new NonceCheckController(); const redirectBypassController = new RedirectBypassController(); export function init(sdk: SDK) { @@ -25,15 +26,14 @@ export function init(sdk: SDK) { await ScopeDetectionController.scan(sdk, req.getUrl()); await redirectBypassController.testAsync(sdk, req, res); - // isOidcFlow는 비동기 메서드로 변경 - if (await NonceCheckController.isOidcFlow(req, res)) { - await sdk.findings.create({ - title: "OIDC Flow Detected", - description: "The request appears to be part of an OIDC flow.", - request: req, - reporter: "", - }); - } + if (NonceCheckController.isOidcFlow(req, res)) { + await sdk.findings.create({ + title: "OIDC Flow Detected", + description: "The request appears to be part of an OIDC flow.", + request: req, + reporter: "", + }); + } }); sdk.events.onInterceptRequest(async (sdk, req: Request) => {