--- name: mobile description: "Review mobile link association, client configuration, and backend APIs as complementary controls with server-owned authorization." --- # Mobile links and API hosts Review mobile link association, client configuration, and backend APIs as complementary controls with server-owned authorization. Defensive study and review of artifacts supplied by their owner. Record missing evidence as an open question. ## Bring to the review - App link or universal-link association files - Mobile client configuration - API authorization design ## Review guide ### 1. Inventory claimed destinations Document verified domains, path rules, package identifiers, and the user-visible destination for each link class. ### 2. Review handoff state Ensure links do not carry authority that the backend cannot independently validate and expire. ### 3. Trace backend ownership For every mobile API object, verify the server authorizes the current user and tenant, independent of the app UI. ### 4. Minimize local secrets Review storage, logs, and diagnostics so tokens and account data are not exposed beyond the needed boundary. ## What to produce - Link association inventory - Client-to-server authority map - Local data handling notes ## Common mistakes - Trusting a client-side route as authorization - Leaving deep-link state reusable - Treating a configured hostname as ownership proof ## Reading and source context ### Resources - [Authorization Cheat Sheet](https://vulns.co/research/resources/owasp-authorization-cheat-sheet/) - [RFC 10017: OAuth 2.0 for Browser-Based Applications](https://vulns.co/research/resources/rfc-10017-browser-oauth-token-custody/) - [OWASP Logging: trustworthy and minimal application evidence](https://vulns.co/research/resources/owasp-security-logging-evidence-quality/) ### Diagrams - [Delegated authority stays within the approved grant](https://vulns.co/research/diagrams/delegated-grant-authority-continuity/) ### Reports - [Google device grants lost client and permission binding](https://vulns.co/research/reports/google-device-authorization-client-scope-binding-2026/) ## Provenance Editorial guide by vulns.co / GK Data. Updated 2026-10-11. Library snapshot: 2026-10-04; commit d5550c7891119cf1379e235721541c947850a3b3. The guide is an editorial synthesis. Linked records preserve their own sources and review dates. Reader: https://vulns.co/skills/mobile/