Category: Development News

  • RFC 9700: Best Current Practice for OAuth 2 0 Security

    If the attacker is able to send the authorization response to an attacker-controlled URI, the attacker will directly get access to the fragment carrying the access token.¶ If the attacker impersonates a public client, the attacker can exchange the code for tokens at the respective token endpoint.¶ If an automatic approval of the authorization is…