SEC: Remove token from URL after reading

Signed-off-by: Knut Ahlers <knut@ahlers.me>
This commit is contained in:
Knut Ahlers 2021-07-11 16:13:29 +02:00
parent 18d06a8926
commit 2eae3b8266
Signed by: luzifer
GPG key ID: 0066F03ED215AD7D

1
app.js
View file

@ -290,6 +290,7 @@ new Vue({
mounted() { mounted() {
this.twitchToken = new URLSearchParams(window.location.hash.substr(1)).get('access_token') || null this.twitchToken = new URLSearchParams(window.location.hash.substr(1)).get('access_token') || null
if (this.twitchToken) { if (this.twitchToken) {
window.location.hash = '' // Remove token from hash for security
this.initChart() this.initChart()
} }
}, },