Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Why does replaying auth code gives access to resources #3

Open
neodragonwarrior opened this issue Apr 6, 2021 · 2 comments
Open

Why does replaying auth code gives access to resources #3

neodragonwarrior opened this issue Apr 6, 2021 · 2 comments

Comments

@neodragonwarrior
Copy link

neodragonwarrior commented Apr 6, 2021

I believe Auth code grant flow is in use in the photoprint/gallery web application demo. I am sending response type=code in the request and in response , I am getting auth code, if I use this to access resources without providing client id+secret , am able to get access to resource pcitures .
Am I missing something here or is it a flaw there ?

@koenbuyens
Copy link
Owner

koenbuyens commented Apr 6, 2021 via email

@neodragonwarrior
Copy link
Author

Yea I didn't forget that , but people tend to mistake it as Access token , where they actually replayed auth code , I saw youtube videos explaining Oauth flaws using this app that way .
Here auth code itself is enough to grant access is not that a common vulnerability I thought.
Anyways thanks much for the response , looking forward for more updates to this app , Great work

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants