I could not sleep, so I wrote an article in English.

Please have a look if you are interested:

Relationship between OAuth and CX, and OAuth vulnerability

Incidentally, CX is not affected by this attack. Also, I have a feeling that the FIX being considered for OAuth does not address the fundamental issue…

Related posts

OAuth PKCE Published as RFC7636

OAuth PKCE (pronounced “pixy”), for which John Bradley (Ping), Naveen Agarwal (Google), and I are credited as co-authors, has been published as [RFC 7636]. It was…

OAuth · 2015-09-18