Can someone explain the “Covert Redirect” vulnerability in OAuth and OpenID?security.stackexchange.com·3 pts·markolschesky·0