Re: [OAUTH-WG] Edge case in RFC 7636, Server Verifies code_verifier facilitates Login-CSRF

2022-01-05 Thread Christopher Burroughs
Greetings, Is this scenario any different from a PKCE downgrade attack, as described in OAuth 2.0 Security Best Current Practice section 4.8.2 ? Warm regards and happy new year! Christopher Burroughs Original Message On Jan 5, 2022, 21:29, Benjamin Häublein wrote: >

Re: [OAUTH-WG] Proposed OAuth Security BCP text on the use of CORS

2023-03-09 Thread Christopher Burroughs
Greetings, I apologize in advance if this question (my first in this list!) is silly :) Regarding CORS support for the authorization endpoint, what about "web message" silent refresh flows? While it never became an RFC, I reckon it is implemented in quite a few places. Is this pattern generally