Hacker News
new
|
past
|
comments
|
ask
|
show
|
jobs
|
submit
login
johncolanduoni
on Oct 22, 2023
|
parent
|
context
|
favorite
| on:
Stealing OAuth tokens of Microsoft accounts via op...
Don't attach the sensitive URL parameters to the second redirect. The first redirect logs you in via cookie, and then if the second redirect is on the right origin it will have access to your cart.
Guidelines
|
FAQ
|
Lists
|
API
|
Security
|
Legal
|
Apply to YC
|
Contact
Search: