As far as I know, dataverse generates nonce to avoid replay attacks when initiating OpenID flow. However, I am still not sure if dataverse really checks the nonce coming back from OpenID provider. Any idea?
Sorry, I have no idea. Oliver or Johannes might.
Last updated: Oct 30 2025 at 06:21 UTC