Homestyx hydra

R1:7176240717f2

Whitelist controllers which can receive a 'code' parameter

Summary:
Ref T4593. There are a variety of clever attacks against OAuth which involve changing the redirect URI to some other URI on the same domain which exhibits unexpected behavior in response to an OAuth request. The best approach to dealing with this is for providers to lock to a specific path and refuse to redirect elsewhere, but not all providers do this.

We haven't had any specific issues related to this, but the anchor issue in T4593 was…
Repository: R1 hydra
Commit Date: Mar 12 2014