3 ms·
An attacker could call the post back with a code generated for another client_id. When you use the code to query who logged in, Facebook will still respond, eve
by michaeljx 3y ago
An attacker could call the post back with a code generated for another client_id. When you use the code to query who logged in, Facebook will still respond, even if the code was not generated for your client_id
- rosswilson 3y agoThis shouldn't be possible as the server-to-server request to Facebook to exchange the Authorization Code for an Access Token requires the client_id and client_secret to be provided. Facebook should (though I haven't actually confirmed this) verify that the code was issued to the given client_id. If the code was issued for client 123, when client 456 tries to exchange it for an Access Token Facebook should throw an error.
- michaeljx 3y agoYup that's the thing, Facebook doesn't do that. The token is the only thing needed, no validation on their half if it matches a client id