KMINGON
|
1bc442b1d3
|
[FIX]: tokenType까지 검사하여 OAuth Flow인지 확인
|
2025-06-04 17:01:32 +09:00 |
|
KMINGON
|
b1c10b0739
|
Merge branch 'main' into feature/access-token-detector
|
2025-06-02 00:22:04 +09:00 |
|
김민곤
|
db242c4465
|
Merge pull request #12 from whs-authz-authn-project/feature/csrf
데일리스크럼 코드리뷰에서 2차 확인까지 마쳐서 merge 진행
|
2025-06-02 00:21:20 +09:00 |
|
KMINGON
|
96452cf9fa
|
Merge branch 'feature/access-token-detector' of https://github.com/whs-authz-authn-project/caido-plugin-test into feature/access-token-detector
|
2025-06-01 21:00:04 +09:00 |
|
KMINGON
|
77a65002f7
|
[FIX]: 탐지 키워드 정상화
|
2025-06-01 20:59:48 +09:00 |
|
tv0924@icloud.com
|
2010b85c4d
|
[Fix] 특정 경우에서 csrf 방지 토큰이 없다고 판별한 것을 수정
|
2025-06-01 20:14:10 +09:00 |
|
sultanofdisco
|
3a8fb9a401
|
Merge pull request #10 from whs-authz-authn-project/sujin
nonceCheck 수정
|
2025-05-31 15:56:04 +09:00 |
|
sultanofdisco
|
77a05bb707
|
nonceCheck 수정3
|
2025-05-31 15:42:37 +09:00 |
|
sultanofdisco
|
e7f9d5684b
|
Merge branch 'main' of https://github.com/whs-authz-authn-project/caido-plugin-test into sujin
|
2025-05-31 15:27:30 +09:00 |
|
imnyang
|
907fcd8120
|
Remove pkce
|
2025-05-31 15:02:27 +09:00 |
|
sultanofdisco
|
252400a911
|
nonceCheck 수정2
|
2025-05-31 14:39:20 +09:00 |
|
김민곤
|
b801fdda0b
|
Merge pull request #9 from whs-authz-authn-project/feature/access-token-detector
Feature/access token detector
|
2025-05-31 12:57:02 +09:00 |
|
김민곤
|
a2b7d44ec0
|
Merge branch 'main' into feature/access-token-detector
|
2025-05-31 12:48:11 +09:00 |
|
KMINGON
|
f1b5ef5f9b
|
REFACTOR : findings를index가 아닌 모듈애서 만들도록 수정
|
2025-05-31 12:37:54 +09:00 |
|
암냥 (imnyang)
|
d9353220e6
|
Update README.md
|
2025-05-31 12:03:49 +09:00 |
|
암냥 (imnyang)
|
a3fcf28786
|
Merge pull request #7 from whs-authz-authn-project/feature/scope
[Add] Scope Detection
|
2025-05-31 12:02:31 +09:00 |
|
암냥 (imnyang)
|
307d373b9c
|
Merge branch 'main' into feature/scope
|
2025-05-31 12:01:58 +09:00 |
|
KMINGON
|
7b704cacf4
|
STYLE : 로그 수정
|
2025-05-31 11:56:47 +09:00 |
|
KMINGON
|
858dfd16dc
|
FEAT : AccessToken 및 각종 토큰 존재 여부 확인하는 controller 작성, 테스트 필요
|
2025-05-31 11:56:47 +09:00 |
|
imnyang
|
b1f3534e1c
|
포팅은 했는데 테스트는 안해보긴 했어요 테스트좀 해주세요
|
2025-05-31 11:55:15 +09:00 |
|
sultanofdisco
|
cc81947bd8
|
nonceCheck 수정
|
2025-05-31 11:55:06 +09:00 |
|
김민곤
|
315e38a726
|
Merge pull request #3 from whs-authz-authn-project/feature/csrf
Feature/csrf
|
2025-05-31 11:49:40 +09:00 |
|
seungyeoncherry
|
dfeab629d7
|
[Add] Scope Detection
|
2025-05-31 11:49:11 +09:00 |
|
tv0924@icloud.com
|
5fed2eb7d0
|
[Update] index
|
2025-05-31 11:47:52 +09:00 |
|
암냥 (imnyang)
|
dcb91d141f
|
Merge branch 'main' into feature/csrf
|
2025-05-31 11:41:54 +09:00 |
|
James
|
19b6cb788c
|
Merge pull request #2 from whs-authz-authn-project/imnyang
feature: PKCE Downgrade
|
2025-05-31 11:38:48 +09:00 |
|
imnyang
|
b64c8cc4e4
|
[Add] PKCE 완
|
2025-05-28 23:28:31 +09:00 |
|
tv0924@icloud.com
|
ef1d8f40b3
|
[Update] feature
|
2025-05-28 16:49:48 +09:00 |
|
tv0924@icloud.com
|
f775282e91
|
[Add] csrf
|
2025-05-28 15:01:53 +09:00 |
|
tv0924@icloud.com
|
5042a108d8
|
[Add] csrf
|
2025-05-28 14:56:14 +09:00 |
|
tv0924@icloud.com
|
366f90e5a8
|
[Add] csrf 테스트 추가
|
2025-05-28 14:30:55 +09:00 |
|
tv0924@icloud.com
|
e868cbec67
|
csrf(state) 관련 취약점 탐지 기능 추가
|
2025-05-28 14:17:24 +09:00 |
|
imnyang
|
0a24c5594d
|
[Add] PKCE 체크 및 관련 기능 구현, Playground 디렉토리 정리
|
2025-05-26 00:56:03 +09:00 |
|
imnyang
|
ba20dd9007
|
제가 코드 통일성이 없었네요...
|
2025-05-25 22:28:56 +09:00 |
|
암냥 (imnyang)
|
11b6e479dd
|
Merge pull request #1 from whs-authz-authn-project/imnyang
PKCE Plugin
|
2025-05-25 20:55:57 +09:00 |
|
imnyang
|
2e1eb7a3ab
|
PKCE Downgrade만 체킹한다고요? 아뇨 이제 PKCE가 있는지도 확인할겁니다.
이거도 좀 줄이고
|
2025-05-25 20:55:19 +09:00 |
|
imnyang
|
a5e48ed374
|
[Add] 모든 브랜치로 적용
|
2025-05-25 20:38:36 +09:00 |
|
imnyang
|
2601997ed5
|
GitHub Actions, PKCE Downgrade 추가, PlayGround 추가
|
2025-05-25 20:37:18 +09:00 |
|
imnyang
|
12f635c77b
|
What's happening!!
|
2025-05-25 16:59:51 +09:00 |
|
sultanofdisco
|
c355038288
|
nonce check
oidc flow인지 check하고, nonce 유무를 체크한다
|
2025-05-24 14:25:44 +09:00 |
|
tv0924@icloud.com
|
f901464c3a
|
[Remove] backend build file
|
2025-05-19 12:15:33 +09:00 |
|
tv0924@icloud.com
|
b41b086980
|
[Remove] backend build file
|
2025-05-19 12:13:43 +09:00 |
|
tv0924@icloud.com
|
cc52c85fd5
|
[File] caido에서 바로 사용할 수 있는 zip 파일 추가
|
2025-05-19 11:12:18 +09:00 |
|
tv0924@icloud.com
|
889d7cfbf2
|
[Add] is authZ|implict grant type
|
2025-05-19 11:08:20 +09:00 |
|
James
|
d21ee1eac0
|
Initial commit
|
2025-05-19 11:02:40 +09:00 |
|