Skip to main content

binding_matches

Function binding_matches 

Source
pub fn binding_matches(stored_hash: &str, presented: Option<&str>) -> bool
Expand description

Whether the cookie presented at the callback is the one this flow issued.

An absent cookie never matches. A callback with no cookie is, by definition, not the browser that started the flow — treating that as “no binding recorded, allow” would remove the protection entirely for exactly the request it exists to stop. An empty stored hash does not become a wildcard either.