๐Ÿ” POC: OAuth redirect_to Whitelist Bypass Test

ๆต‹่ฏ•็›ฎๆ ‡๏ผšhttps://auth.onekey.so/auth/v1/authorize
ๆต‹่ฏ•็‚น๏ผšSupabase ๆ˜ฏๅฆๅฏน redirect_to ๅ‚ๆ•ฐๅšไบ†ไธฅๆ ผ็™ฝๅๅ•ๆ ก้ชŒ
ไป…้™ๆŽˆๆƒๅฎ‰ๅ…จๆต‹่ฏ•

้…็ฝฎๅ‚ๆ•ฐ
Supabase URL
https://auth.onekey.so
Anon Key๏ผˆๆบ็  authConsts.ts:202๏ผŒๅ…ฌๅผ€ๅ€ผ๏ผ‰
eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJyb2xlIjoiYW5vbiIsImlzcyI6InN1cGFiYXNlIiwiaWF0IjoxNzY5MTc1MzMxLCJleHAiOjE5MjY4NTUzMzF9.d0Zd8eBV8L_EcKDXiJRNTEYGw-dX6IdyDCr0nvOiLqg
redirect_to๏ผˆๆœฌ้กต้ข URL๏ผŒ้ž็™ฝๅๅ•ๅŸŸๅ๏ผ‰
OAuth Provider
apple
ๅฝ“ๅ‰็Šถๆ€
็ญ‰ๅพ…ๆ“ไฝœ...
ๆ“ไฝœ