4 ms·
Just to be sure, how is Google's OAuth2 implementation vulnerable to this? As I understand it: the attacker exploits the fact that your application does not va
by thsealienbstrds 12y ago
Just to be sure, how is Google's OAuth2 implementation vulnerable to this?
As I understand it: the attacker exploits the fact that your application does not validate the redirect_uri parameter. Google's API keys all have whitelists for redirect_uri's. So those can't be exploited, right? Then the only problem is that those redirect_uri's themselves can perform redirects (in Google's case you can put arbitrary data in the 'state' get parameter so you could put another redirect_uri in there) but you can validate those too (on your whitelisted redirect_uri page... and you are advised to do CSRF checks anyway). So in this case, where is the vulnerability? I don't see it.