From the OAuth project, implicit section :
When issuing an access token during an implicit grant flow, the authorization server does not authenticate the client.
Now suppose the following:
client_id
redirect_uri
fb://blabla
Is there any way to prevent this?
:
, , , .
, . , , clientId, , .
, . , ( ), , / - .
, , , , " ", , 2 URL ( URI ), , ...
Source: https://habr.com/ru/post/1679010/More articles:What are the requirements for functor accumulation? - c ++Как я могу применить класс к тому, что действует как класс во время выполнения? - javaHow to split a CString in which there are no delimiters? - c ++How can OpenId Connect protect a resource server from impersonating a client? - securityHow to prove Theorem 3.5.4 in "Types and programming languages" using Coq? - proofSwift 4 - Subclass General constraints on the associated type - genericsCannot resolve "loader loader" - node.jsSource maps in webpack compiler + closures - webpackРекомендован ли F # Guidate объявить тип модуля и его имя? - moduleUsing Lerna with Unpublished Packages - lernaAll Articles