Open cardosec

Case DAF3EC · Web AppSec · L4 Advanced

OAuth 2.0 Flow Attacks

Practise as: Deep dive
  1. 01 Context
  2. 02 Mechanism
  3. 03 Lessons
What a strong answer covers

Try it out loud first. Then check yourself:

  1. Authorization code flow with PKCE is the recommended flow for all clients; implicit flow is deprecated
  2. Missing state parameter enables login CSRF; loose redirect_uri matching leaks codes to attacker hosts
  3. PKCE binds the code to a code_verifier so an intercepted authorization code cannot be redeemed
  4. Mix-up and token substitution attacks: validate issuer and audience; use OIDC nonce for ID tokens
  5. Store refresh tokens securely and use rotation with reuse detection for public clients

If the interviewer pushes back

  • Why does PKCE matter for confidential clients too, not just mobile and SPA apps?

Go deeper

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.