Collected research
Attacks via a New OAuth flow, Authorization Code Injection, and Whether HttpOnly, PKCE, and BFF Can Help
Attacks via a New OAuth flow, Authorization Code Injection, and Whether HttpOnly, PKCE, and BFF…
An attacker who can run script on any page of an OAuth client's origin starts a fresh authorization code flow in a hidden frame, breaks the flow so the application never consumes the code, and replays the stolen authorization response from their own machine. This yields an authenticated session even with a confidential client, a backend-for-frontend, PKCE, state and nonce.
Record
- Document
- Attacks via a New OAuth flow, Authorization Code Injection, and Whether HttpOnly, PKCE, and BFF…
- Researcher
- Andrey Kuznetsov
- Published by
- Medium
- Date
- Topic
- HTTP
In the archive
Related sources
- Talk discussed and critiqued
- Earlier OAuth attack presentation Whitepaper
- OAuth demonstration application
- Russian version
Tags
This page is the archive's own catalogue record. The research is the work of Andrey Kuznetsov, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .