Skip to content

Commit c9d33dd

Browse files
committed
rm csrf mention
1 parent f9271f9 commit c9d33dd

File tree

1 file changed

+0
-3
lines changed

1 file changed

+0
-3
lines changed

docs/specification/draft/basic/authorization.mdx

Lines changed: 0 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -289,7 +289,4 @@ MCP clients **MUST** have redirect URIs registered with the authorization server
289289

290290
Authorization servers **MUST** validate exact redirect URIs against pre-registered values to prevent redirection attacks.
291291

292-
MCP clients **SHOULD** use and verify state parameters in the authorization code flow
293-
and discard any results that do not include or have a mis-match with the original state.
294-
295292
Authorization servers **MUST** take precautions to prevent redirecting user agents to untrusted URI's, following suggestions laid out in [OAuth 2.1, Section 7.12.2](https://datatracker.ietf.org/doc/html/draft-ietf-oauth-v2-1-12#section-7.12.2)

0 commit comments

Comments
 (0)