Case DAF3EC · Web AppSec · L4 Advanced
OAuth 2.0 Flow Attacks
Practise as: Deep dive
- 01 Context
- 02 Mechanism
- 03 Lessons
What a strong answer covers
Try it out loud first. Then check yourself:
- Authorization code flow with PKCE is the recommended flow for all clients; implicit flow is deprecated
- Missing state parameter enables login CSRF; loose redirect_uri matching leaks codes to attacker hosts
- PKCE binds the code to a code_verifier so an intercepted authorization code cannot be redeemed
- Mix-up and token substitution attacks: validate issuer and audience; use OIDC nonce for ID tokens
- Store refresh tokens securely and use rotation with reuse detection for public clients
If the interviewer pushes back
- Why does PKCE matter for confidential clients too, not just mobile and SPA apps?
Go deeper
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.