mirror of
https://github.com/NousResearch/hermes-agent.git
synced 2026-09-28 06:45:17 +08:00
_fetch_discovery followed redirects but only pinned the document's self-asserted issuer field, so one cleartext or attacker-hosted hop could serve a forged document claiming the configured issuer with attacker jwks_uri and token_endpoint. Verify then accepted attacker-signed ID tokens and the code exchange POSTed the client secret to the attacker's token endpoint. The resolved response.url must now share the configured issuer's origin (scheme, host, port with default-port normalisation) before the body is parsed. Same-origin canonicalisation redirects still pass, and the issuer-field pin remains as the misconfig check it is.