@aaronpk Yes, i get that, but the attacker can make the access token request just as easily as the legitimate client.
WeChat ID
aaronpk_tv
@aaronpk Yes, i get that, but the attacker can make the access token request just as easily as the legitimate client.
@aaronpk you linked to "Insufficient Redirect URI Validation" though? maybe i'm just confused about what you were talking about.