diff --git a/src/flow/evil.html b/src/flow/evil.html new file mode 100644 index 0000000..9ea15ab --- /dev/null +++ b/src/flow/evil.html @@ -0,0 +1,72 @@ + + + + + + + OAuth 2.0 Playground - Authorization Code Flow (2/3) + + + + + + + + + + + + + + + + +
+
+
+

+
+ + +
+
+
+
+
+
Let's see what we have here:
+
+

+ Out evil attacker now can use these to finish the flow on your behalf and access your data. +

+
+
+
+
+
+ +
+
+ + + + + + \ No newline at end of file diff --git a/src/img/evil.webp b/src/img/evil.webp new file mode 100644 index 0000000..277db99 Binary files /dev/null and b/src/img/evil.webp differ