Tag
Notes tagged “jwt”
Every note filed under jwt, newest first.
A filtered view of the notes.
2026
- One Defect, Three Surfaces
CORS allowlists, OAuth redirect URIs and open redirects have separate vulnerability literatures and the same bug — a structured identifier tested with a string operation. The fix is one sentence, and a standards body finally wrote it down.