Redirect URI validation protects token delivery

In an authorisation flow, the redirect address is where the credential gets delivered.

If a service accepts any address, or matches loosely, an attacker can have it delivered to them. Exact matching against a registered list is the control, and permissive matching, wildcards or open redirects in the same domain are the recurring ways this goes wrong.

More on OAuth and federation