OAuth Authorization-Code Attacks
Common attack surfaces on OAuth 2.0 authorization-code flow.
Rendering…
Make it your own.
digraph oauth {
rankdir=LR;
graph [bgcolor=transparent];
node [shape=box, style="rounded,filled", fontname=Inter, fontsize=10];
U [label="User browser", fillcolor="#dbeafe"];
C [label="Client app", fillcolor="#dbeafe"];
A [label="Auth server", fillcolor="#dcfce7"];
R [label="Resource server"];
U -> C [label="login"];
C -> A [label="/authorize"];
A -> U [label="redirect + code"];
U -> C [label="code"];
C -> A [label="/token (code + secret)"];
A -> C [label="access_token"];
C -> R [label="Bearer"];
Attack1 [label="Open redirect →\ncode theft", shape=ellipse, fillcolor="#fee2e2"];
Attack2 [label="CSRF — no state param", shape=ellipse, fillcolor="#fee2e2"];
Attack3 [label="Code interception →\nuse PKCE", shape=ellipse, fillcolor="#fee2e2"];
Attack4 [label="Mix-up — token sent\nto wrong AS", shape=ellipse, fillcolor="#fee2e2"];
Attack1 -> U [style=dashed];
Attack2 -> A [style=dashed];
Attack3 -> U [style=dashed];
Attack4 -> C [style=dashed];
}