Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

Handling of `state` parameter in Authentication: Update spec so clients are required to send `state` parameter

Open
#41 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
3/5
Estimated time
1-2 days
Newbie friendliness
42/100
Issue type
Documentation
Clarity
Mostly clear
Activity status
Stale

Research direction

Read the Authentication specification and issue #40 first, then locate the normative text governing the state parameter. Update the next-major-version wording so clients must send state while servers are not required to reject requests that omit it, and verify the requirement is stated consistently.

Written by the indexing model from the issue text.

Description

For the next major version, clients are required to send the state parameter. But servers are not required to fail a request that misses it.

See also #40.

Dominant language
No language data
Stars
39
Forks
9
PR merge metrics
No merged PRs in 30d

Getting set up

This project ships no dev container, Dockerfile or contributing guide, so setting up is up to you: start from its README, and see our first-contribution guide for the general steps.

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from buildingSMART/foundation-API

All issues in buildingSMART/foundation-API

Similar issues

More Security issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.