3 ms·
> OAuth also uses an “explicit grant type,” which is similar to “implicit grant type” but the server (randomsite.com) receives a code instead of a token and nee
by raselhanout 3y ago
> OAuth also uses an “explicit grant type,” which is similar to “implicit grant type” but the server (randomsite.com) receives a code instead of a token and needs to make an additional request to Facebook to exchange it for a token. We’re using the implicit grant type example here because it is easier to understand and relevant to this post.
Are the first two attacks possible with explicit grant ? Wouldn't the auth server return an error if the client tried to request the access token with their secret and the code from another client ?
- sigwinch28 3y agoNo, they’re not possible. Yes, the auth server would return an error because the token is retrieved by the server out-of-band (Mallory can’t intercept via the browser) and must provide its credentials to Facebook to retrieve said token. Additionally, Facebook SHOULD check that the client using the code is the same client that initiated the OAuth flow.