Justin Richer
1 min readMay 9, 2019

--

The call to get the access token happens in the back channel, so an attacker that’s sitting in the browser or camping on the redirect URIs will never see the back-channel call.

--

--

Justin Richer
Justin Richer

Written by Justin Richer

Justin Richer is a security architect and freelance consultant living in the Boston area. To get in touch, contact his company: https://bspk.io/

No responses yet