Hey

At the September 21 interim [1], the chairs asked if there authorization
code exfiltration is a problem to be solved. 3 said yes, 5 said no.


The authorization code is a credential that we deliver in the redirect URL.
>From there it can be exfiltrated through history, logs, Referer, page
JavaScript and extensions. Based on the Browser-Swapping thread [2] and the
support for Redirect Headers in December [3], I had thought there was
consensus that this is a problem.


Do you think exfiltration of the authorization code is a problem this WG
should solve?


/Dick


[1] https://datatracker.ietf.org/meeting/interim-2026-oauth-05/session/oauth

[2] https://mailarchive.ietf.org/arch/msg/oauth/K8Wnw08GzPstyAQAh0JmSB47pOQ/

[3] https://mailarchive.ietf.org/arch/msg/oauth/FFkUlOiz7I4K03pqjMfIFkxAwA8/
_______________________________________________
OAuth mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to