← All changes
|
vendor/wp-media/mcp-oauth/inc/Auth/AuthorizeEndpoint.php
+4
-1
2.3.2
→
trunk
View file →
| @@ -258,9 +258,12 @@ | ||
| 258 | 258 | * @return void |
| 259 | 259 | */ |
| 260 | 260 | private function send_error( string $redirect_uri, string $error, string $state ): void { |
| 261 | 261 | if ( '' !== $redirect_uri ) { |
| 262 | - $params = [ 'error' => $error ]; | |
| 262 | + $params = [ | |
| 263 | + 'error' => $error, | |
| 264 | + 'iss' => home_url(), | |
| 265 | + ]; | |
| 263 | 266 | if ( '' !== $state ) { |
| 264 | 267 | $params['state'] = $state; |
| 265 | 268 | } |
| 266 | 269 | wp_redirect( add_query_arg( $params, $redirect_uri ) ); // phpcs:ignore WordPress.Security.SafeRedirect.wp_redirect_wp_redirect -- redirecting to the client's own registered redirect_uri, already validated against the CIMD allowlist; not a same-site redirect. |