Source reading · RFC 9700, BCP 240 · Lodderstedt, Bradley, Labunets, Fett 2025 · the OAuth 2.0 Security BCP's attacker model and attack catalog, walked as a testing tool
This is a source reading of RFC 9700, the OAuth 2.0 Security Best Current Practice, not a general survey of OAuth attacks. Its attacker model and 16 named attacks are turned into an attacker model reference, a flow-by-flow attack surface map, a searchable exploit catalog, and two working checklists cross-referenced against OpenID Connect Core 1.0 for ID Token handling. Built for authorized security testing.