OAuth 2 0 Security Best Current Practice RFC 9700
An attacker can use this vector to obtain the user’s authentication credentials, change the scope of access granted to the client, and potentially access the user’s resources.¶ A user believing to interact with that context, for example, by clicking on buttons, inadvertently interacts with the authorization endpoint user interface instead. In such an attack, an … 더 읽기