๐ POC: OAuth redirect_to Whitelist Bypass Test
ๆต่ฏ็ฎๆ ๏ผhttps://auth.onekey.so/auth/v1/authorize
ๆต่ฏ็น๏ผSupabase ๆฏๅฆๅฏน redirect_to ๅๆฐๅไบไธฅๆ ผ็ฝๅๅๆ ก้ช
ไป
้ๆๆๅฎๅ
จๆต่ฏ
้
็ฝฎๅๆฐ
Supabase URL
https://auth.onekey.so
Anon Key๏ผๆบ็ authConsts.ts:202๏ผๅ
ฌๅผๅผ๏ผ
eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJyb2xlIjoiYW5vbiIsImlzcyI6InN1cGFiYXNlIiwiaWF0IjoxNzY5MTc1MzMxLCJleHAiOjE5MjY4NTUzMzF9.d0Zd8eBV8L_EcKDXiJRNTEYGw-dX6IdyDCr0nvOiLqg
redirect_to๏ผๆฌ้กต้ข URL๏ผ้็ฝๅๅๅๅ๏ผ
OAuth Provider
apple
ๅฝๅ็ถๆ
็ญๅพ
ๆไฝ...
ๆไฝ
PKCE ๅๆฐ๏ผๆฌๅฐ็ๆ๏ผ
code_verifier
code_challenge๏ผSHA-256 base64url๏ผ
ๆ้ ็ OAuth URL๏ผๅณๅฐ่ทณ่ฝฌ๏ผ
ๅ่ฐ็ปๆ
ๆ่ทๅฐ็ๆๆ็ auth_code
Supabase state