OAuth Recommendations for Single-page Apps
Single-page applications (SPAs) are often protected by a homegrown single sign-on (SSO) solution, which may leave them open to security risks. Get Ping Identity’s recommendations and best practices for integrating OAuth and OpenID Connect with SPAs to harden browser-based apps against common threats.
oauth  keycloak 
6 days ago by jonasbehmer
A reverse proxy that provides authentication with Google, Github or other provider
OAuth  identity  proxy  nginx 
9 days ago by activescott
Facebook’s OAuth problem - Alex Bilbie
redirect_uri can be not only app’s domain, but facebook.com domain is also allowed. In our exploit we used response_type=token,signed_request&redirect_uri=FB_PATH where FB_PATH was a specially crafted URL to disclose these values..
oauth  security  login 
19 days ago by adamcohenrose

