You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Additionally, implicit clients can be subject to a further kind of attack.
It would be nice to clarify that both implicit clients and non-implicit clients using providers that support response_mode=fragment can be subject to this attack.
The text was updated successfully, but these errors were encountered:
See also oauth-wg/oauth-browser-based-apps#52 for why I care about this. Performant browser-based apps prefer response_mode=fragment with the authorization code flow.
Microsoft Entra supports response_mode=fragment from https://openid.net/specs/oauth-v2-multiple-response-types-1_0.html. Microsoft Entra's browser-based apps library (https://github.com/AzureAD/microsoft-authentication-library-for-js) uses this mode with the authorization code flow. The draft says:
It would be nice to clarify that both implicit clients and non-implicit clients using providers that support response_mode=fragment can be subject to this attack.
The text was updated successfully, but these errors were encountered: