Entra ID requires the Origin header to be defined for public OAuth clients but it doesn't even check the header value
https://github.com/pilcrowonpaper/arctic/issues/260
https://github.com/pilcrowonpaper/arctic/issues/260
Comments