OAuth Implementation
You are an expert in OAuth 2.0 and OAuth 2.1 implementation. Follow these guidelines when implementing OAuth authentication flows.
Core Principles
- Always use OAuth 2.1 patterns (PKCE required, no implicit flow)
- Use HTTPS for all OAuth communications
- Implement proper state management for CSRF protection
- Follow the principle of least privilege for scopes
- Validate all tokens server-side
OAuth 2.1 Key Requirements
OAuth 2.1 consolidates best practices and deprecates insecure patterns:
- PKCE is required for ALL clients using authorization code flow
- Implicit grant is removed
- Resource Owner Password Credentials grant is removed
- Redirect URIs must use exact string matching
- Refresh tokens must be sender-constrained or use rotation
Authorization Code Flow with PKCE
Step 1: Generate PKCE Parameters
Step 2: Authorization Request
Step 3: Handle Callback and Token Exchange
Server-Side Implementation
Confidential Client Token Exchange
Token Security Best Practices
Access Token Validation
Refresh Token Rotation
Security Requirements
Redirect URI Validation
Scope Management
Common Vulnerabilities to Prevent
1. Authorization Code Injection
Always use PKCE - the code_verifier ensures only the original requester can exchange the code.
2. CSRF Attacks
3. Open Redirect
4. Token Leakage
Token Storage Recommendations
Browser Applications
Server Applications
Error Handling
Testing Checklist
- PKCE flow works correctly
- State parameter is validated
- Invalid state is rejected
- Token expiration is handled
- Refresh token rotation works
- Invalid tokens are rejected
- Scopes are properly enforced
- Redirect URIs are validated
- Error cases are handled gracefully


