授权 code 原先以 query 形式发给 /system/sso/callback,会被 nginx access log、浏览器历史和 Referer 捕获。改走 POST body,与后端 @RequestBody SsoCallbackReqVO 对齐,避免一次性码泄露给中间层。 Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
授权 code 原先以 query 形式发给 /system/sso/callback,会被 nginx access log、浏览器历史和 Referer 捕获。改走 POST body,与后端 @RequestBody SsoCallbackReqVO 对齐,避免一次性码泄露给中间层。 Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>