25 ms·
While what you're saying applies to OAuth in general, there are a lot less variables in this situation. This was specifically "Sign in with.." so we know it wa
by caseysoftware 3y ago
While what you're saying applies to OAuth in general, there are a lot less variables in this situation.
This was specifically "Sign in with.." so we know it was OpenID Connect which mandates signed JWTs for ID tokens. Those JWTs would have an issuer (the social provider) to determine their source and the client id (to determine the intended app) so those aren't in question here.
Further, since these are ID tokens, they WOULD provide authentication information (technically identity info) and minimal authorization info.