Hey
At the September 21 interim [1], the chairs asked if there authorization code exfiltration is a problem to be solved. 3 said yes, 5 said no. The authorization code is a credential that we deliver in the redirect URL. >From there it can be exfiltrated through history, logs, Referer, page JavaScript and extensions. Based on the Browser-Swapping thread [2] and the support for Redirect Headers in December [3], I had thought there was consensus that this is a problem. Do you think exfiltration of the authorization code is a problem this WG should solve? /Dick [1] https://datatracker.ietf.org/meeting/interim-2026-oauth-05/session/oauth [2] https://mailarchive.ietf.org/arch/msg/oauth/K8Wnw08GzPstyAQAh0JmSB47pOQ/ [3] https://mailarchive.ietf.org/arch/msg/oauth/FFkUlOiz7I4K03pqjMfIFkxAwA8/
_______________________________________________ OAuth mailing list -- [email protected] To unsubscribe send an email to [email protected]
