Skip to content

OAuth Profile should mandate RFC7636 (PKCE) for code flow #11

Description

@bitbucket-import-issues

Originally submitted by Nat (Nat Sakimura) on 2016-08-02

There is going to be a demonstration of Browser TLS intercept at Blackhat today. (WPAD Attack).

There is a news article as well: New attack bypasses HTTPS protection on Macs, Windows, and Linux

We knew of the possibility but not it has become the reality.

Given the situation, mandating RFC7636 for all the Clients (including confidential clients) for code flow seems prudent.


Bitbucket status: closed

Bitbucket origin: issue 11

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Fields

    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions