Skip to content
Graphviz (DOT) templates

OAuth Authorization-Code Attacks

Common attack surfaces on OAuth 2.0 authorization-code flow.

Template previewGraphviz (DOT)
Rendering…

Make it your own.

digraph oauth {
  rankdir=LR;
  graph [bgcolor=transparent];
  node [shape=box, style="rounded,filled", fontname=Inter, fontsize=10];

  U [label="User browser", fillcolor="#dbeafe"];
  C [label="Client app", fillcolor="#dbeafe"];
  A [label="Auth server", fillcolor="#dcfce7"];
  R [label="Resource server"];

  U -> C [label="login"];
  C -> A [label="/authorize"];
  A -> U [label="redirect + code"];
  U -> C [label="code"];
  C -> A [label="/token (code + secret)"];
  A -> C [label="access_token"];
  C -> R [label="Bearer"];

  Attack1 [label="Open redirect →\ncode theft", shape=ellipse, fillcolor="#fee2e2"];
  Attack2 [label="CSRF — no state param", shape=ellipse, fillcolor="#fee2e2"];
  Attack3 [label="Code interception →\nuse PKCE", shape=ellipse, fillcolor="#fee2e2"];
  Attack4 [label="Mix-up — token sent\nto wrong AS", shape=ellipse, fillcolor="#fee2e2"];

  Attack1 -> U [style=dashed];
  Attack2 -> A [style=dashed];
  Attack3 -> U [style=dashed];
  Attack4 -> C [style=dashed];
}