OAuth signature should be verified against URL provided to the tool.
There is possibility that a proxy will change URL along the way (for example protocol from https to http) which would invalidate signature. Supporting LTI_1 and LTI_2 use case.
Showing
Please
register
or
sign in
to comment