OAuth token theft

OAuth token theft

TL;DR: Redirect_uri quirks, referer leak, postMessage leak, state-less flow, open-redirect chain → attacker captures access / refresh tokens.

Stub — to be filled in.

What it is

TODO

Preconditions / where it applies

TODO

Technique

TODO

Detection and defence

TODO

References