1 min readMay 9, 2019
The call to get the access token happens in the back channel, so an attacker that’s sitting in the browser or camping on the redirect URIs will never see the back-channel call.
The call to get the access token happens in the back channel, so an attacker that’s sitting in the browser or camping on the redirect URIs will never see the back-channel call.
Justin Richer is a security architect and freelance consultant living in the Boston area. To get in touch, contact his company: https://bspk.io/