diff --git a/src/main/java/com/auth0/RandomStorage.java b/src/main/java/com/auth0/RandomStorage.java index 1d5017d..f9510bb 100644 --- a/src/main/java/com/auth0/RandomStorage.java +++ b/src/main/java/com/auth0/RandomStorage.java @@ -15,10 +15,10 @@ class RandomStorage extends SessionUtils { */ static boolean checkSessionState(HttpServletRequest req, String state) { String currentState = (String) remove(req, StorageUtils.STATE_KEY); - if (currentState == null && state == null) { - return true; + if (currentState == null) { + return state == null; } else { - return (currentState != null && currentState.equals(state)); + return currentState.equals(state); } }