OAUTH Audit

Use when auditing OAuth 2.0 / OIDC implementations against RFC 9700 (OAuth Security BCP), reviewing client or authorization-server code, evaluating PKCE / state / redirect-URI handling, hardening token exchange and refresh flows, or triaging suspected OAuth vulnerabilities (CWE-352 CSRF, CWE-287 broken auth).

Lu1sDV e574304 3 files · 19.9 KB Updated

File contents

Lu1sDV/skillsmd/tree/main/oauth-audit commit e574304598

Frequently asked questions

npx skillmds@latest add lu1sdv/oauth-audit