Common CSRF vulnerability in OAuth2 implementations
online24.nl
online24.nl
Maybe you already knew this. Maybe you are too smart to make such a mistake (though in my experience, people quick to dismiss "simple" security practices are the most likely to forget them and make this kind of mistake). Some people aren't. And others, like me (also way-too-smart-to-ever-do something-like-this of course) don't actually know much about OAuth and read the link interested in learning more about its security landscape.