Method MatchesReturnedState
- Namespace
- MailFathom.Common.MailboxOAuth
- Assembly
- MailFathom.Common.dll
MatchesReturnedState(string?)
Reports whether a redirect echoed the value this authorization was issued with.
public bool MatchesReturnedState(string? returnedState)
Parameters
returnedStatestringThe
stateparameter the operator read back from the redirect address.
Returns
Remarks
This is the anti-forgery check, and it lives here rather than in the command that prompts for the value so that it is covered where every other rule about this exchange is. A command is a composition root; a security comparison written there would be reachable only through a console.
The comparison is ordinal and case-sensitive against a value this process generated from cryptographically secure random material, and surrounding whitespace is removed because it comes from a copy and paste rather than from the authorization server. It is not a constant-time comparison: the expected value is not a secret the attacker is trying to learn — it is echoed back through the operator's own browser — and what it proves is that the code arrived from the authorization this process started.