sparse-alarm-2032
05/16/2023, 8:41 PMbreezy-evening-56597
salmon-night-88354
05/16/2023, 8:49 PMsparse-alarm-2032
05/16/2023, 8:57 PMbreezy-evening-56597
sparse-alarm-2032
05/16/2023, 9:02 PMsalmon-night-88354
05/16/2023, 9:04 PMsalmon-night-88354
05/16/2023, 9:07 PMsparse-alarm-2032
05/16/2023, 9:07 PMbreezy-evening-56597
sparse-alarm-2032
05/16/2023, 9:23 PMsalmon-night-88354
05/16/2023, 9:23 PMsparse-alarm-2032
05/16/2023, 9:23 PMsalmon-night-88354
05/16/2023, 9:26 PMsalmon-night-88354
05/16/2023, 9:52 PMorange-belgium-27264
/authenticate
endpoint that you have to serve a plain html/javascript page that upon load would trigger a background fetch to a DIFFERENT endpoint, or maybe just a POST to the same endpoint, and only that would trigger the token validation
btw, all of this does not happen when using Descope Flows, because they do just that, they only run on a real browser so these GET requests from security scanners do not trigger anything
I hope this helps, let me know if you have any additional questions or wanna jump on a callsparse-alarm-2032
05/17/2023, 6:55 PM