Redirect URI validation protects token delivery
In an authorisation flow, the redirect address is where the credential gets delivered.
If a service accepts any address, or matches loosely, an attacker can have it delivered to them. Exact matching against a registered list is the control, and permissive matching, wildcards or open redirects in the same domain are the recurring ways this goes wrong.
More on OAuth and federation
- OAuth consent is not proof of identityThe ticket, not the person
- Token scope defines capabilityIt only presses three
- Bearer tokens behave like cashWhoever picks it up
- SSO concentrates convenience and consequenceOne handle, every gate
- Federation shifts where trust livesThe decision moved house
- Token audience prevents universal reuseA ticket for this gate only
