Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
pwntus_se
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
Authetik (Pun Intended) Vulnerability
(securityblog.omegapoint.se)
2 points
by
pwntus_se
2y ago
|
0 comments
2.
▲
by
pwntus_se
3y ago
You could store that information in the client. Store a reference from the value of the state parameter to the deep link url you want. https://www.rfc-editor.org/rfc/rfc6749#section-4.1.1
3.
▲
by
pwntus_se
3y ago
However, stealing access tokens is only possible with public clients. The open redirect works on both public and confidential clients.
4.
▲
by
pwntus_se
3y ago
I've seen it in multiple installs, and it's used by keycloak's default clients used for the admin app and for the account portals for realms.