OAuth 2.0 / OIDC Attacks
Almost every real OAuth/OIDC bug lives in the gaps the spec leaves to implementers. The Authorization Code flow first, then redirect_uri bypass, missing-state CSRF, PKCE, implicit-flow token leakage, id_token JWT forgery, Mix-Up across multiple IdPs, and scope elevation — walked through one at a time.
Members Only Content
This article is exclusively available to premium members of LazyHackers. Login or subscribe to read.