[bugfix] Assume default code challenge method of s256 (#4241)

Bumps our oauth2 dependency, and uses *default* code challenge method of S256 instead of plain.

Fixes https://codeberg.org/superseriousbusiness/gotosocial/issues/4238

Reviewed-on: https://codeberg.org/superseriousbusiness/gotosocial/pulls/4241
Co-authored-by: tobi <tobi.smethurst@protonmail.com>
Co-committed-by: tobi <tobi.smethurst@protonmail.com>
This commit is contained in:
tobi 2025-06-05 11:29:36 +02:00 committed by tobi
commit 118d4e4d03
6 changed files with 30 additions and 12 deletions

View file

@ -128,6 +128,7 @@ func New(
AllowedCodeChallengeMethods: []oauth2.CodeChallengeMethod{
oauth2.CodeChallengeS256,
},
DefaultCodeChallengeMethod: oauth2.CodeChallengeS256,
},
manager,
)