tl;dr Covert Redirect Vulnerability is a real, if not new, threat when combined with Implicit Grant Flow (not Code flow) This Covert Redirect Vulnerability in OAuth 2 is an interesting one. Thereâs a couple of defending arguments that this isnât a flaw in OAuth itself. While I agree that it isnât a flaw in the protocol, I think the threat is a real one, combined with a) a loose validation on redir
{{#tags}}- {{label}}
{{/tags}}