OAuth

(1)

OAuth is the authorization framework letting applications access resources on a user's behalf without sharing credentials. Coverage of OAuth 2.0 and OIDC flows, token handling and scope design, consent phishing and OAuth abuse by attackers, and the implementation practices that keep delegated access from becoming an intrusion path.