|
|
@ -769,28 +769,28 @@
|
|
|
|
href="#GoogleIss">15.6.2.</a>
|
|
|
|
href="#GoogleIss">15.6.2.</a>
|
|
|
|
Google "iss" Value<br>
|
|
|
|
Google "iss" Value<br>
|
|
|
|
<a href="#RelatedSpecs">15.7.</a>
|
|
|
|
<a href="#RelatedSpecs">15.7.</a>
|
|
|
|
Related Specifications and Implementer's Guides<br>
|
|
|
|
相关的规范与实现指南<br>
|
|
|
|
<a href="#Security">16.</a>
|
|
|
|
<a href="#Security">16.</a>
|
|
|
|
Security Considerations<br>
|
|
|
|
安全性考虑<br>
|
|
|
|
<a href="#RequestDisclosure">16.1.</a>
|
|
|
|
<a href="#RequestDisclosure">16.1.</a>
|
|
|
|
Request Disclosure<br>
|
|
|
|
请求的公开(Disclosure)<br>
|
|
|
|
<a href="#ServerMasquerading">16.2.</a>
|
|
|
|
<a href="#ServerMasquerading">16.2.</a>
|
|
|
|
Server Masquerading<br>
|
|
|
|
服务端的伪造(Masquerading)<br>
|
|
|
|
<a href="#TokenManufacture">16.3.</a>
|
|
|
|
<a href="#TokenManufacture">16.3.</a>
|
|
|
|
Token Manufacture/Modification<br>
|
|
|
|
Token 生成/更新<br>
|
|
|
|
<a
|
|
|
|
<a
|
|
|
|
href="#AccessTokenDisclosure">16.4.</a>
|
|
|
|
href="#AccessTokenDisclosure">16.4.</a>
|
|
|
|
Access Token Disclosure<br>
|
|
|
|
Access Token的公开(Disclosure)<br>
|
|
|
|
<a href="#ResponseDisclosure">16.5.</a>
|
|
|
|
<a href="#ResponseDisclosure">16.5.</a>
|
|
|
|
Server Response Disclosure<br>
|
|
|
|
服务端响应的公开(Disclosure)<br>
|
|
|
|
<a href="#ServerResponseRepudiation">16.6.</a>
|
|
|
|
<a href="#ServerResponseRepudiation">16.6.</a>
|
|
|
|
Server Response Repudiation<br>
|
|
|
|
服务端响应的认可性(Repudiation)<br>
|
|
|
|
<a href="#RequestRepudation">16.7.</a>
|
|
|
|
<a href="#RequestRepudation">16.7.</a>
|
|
|
|
Request Repudiation<br>
|
|
|
|
请求的认可性(Repudiation)<br>
|
|
|
|
<a href="#AccessTokenRedirect">16.8.</a>
|
|
|
|
<a href="#AccessTokenRedirect">16.8.</a>
|
|
|
|
Access Token Redirect<br>
|
|
|
|
Access Token 重定向<br>
|
|
|
|
<a href="#TokenReuse">16.9.</a>
|
|
|
|
<a href="#TokenReuse">16.9.</a>
|
|
|
|
Token Reuse<br>
|
|
|
|
Token的重用<br>
|
|
|
|
<a href="#AuthCodeCapture">16.10.</a>
|
|
|
|
<a href="#AuthCodeCapture">16.10.</a>
|
|
|
|
Eavesdropping or Leaking Authorization Codes (Secondary Authenticator Capture)<br>
|
|
|
|
Eavesdropping or Leaking Authorization Codes (Secondary Authenticator Capture)<br>
|
|
|
|
<a href="#TokenSubstitution">16.11.</a>
|
|
|
|
<a href="#TokenSubstitution">16.11.</a>
|
|
|
|