{
  "slug": "mobile",
  "name": "Mobile links and API hosts",
  "category": "Application",
  "summary": "Review mobile link association, client configuration, and backend APIs as complementary controls with server-owned authorization.",
  "scope": "Defensive study and review of artifacts supplied by their owner. Record missing evidence as an open question.",
  "inputs": [
    "App link or universal-link association files",
    "Mobile client configuration",
    "API authorization design"
  ],
  "review": [
    {
      "title": "Inventory claimed destinations",
      "body": "Document verified domains, path rules, package identifiers, and the user-visible destination for each link class."
    },
    {
      "title": "Review handoff state",
      "body": "Ensure links do not carry authority that the backend cannot independently validate and expire."
    },
    {
      "title": "Trace backend ownership",
      "body": "For every mobile API object, verify the server authorizes the current user and tenant, independent of the app UI."
    },
    {
      "title": "Minimize local secrets",
      "body": "Review storage, logs, and diagnostics so tokens and account data are not exposed beyond the needed boundary."
    }
  ],
  "outputs": [
    "Link association inventory",
    "Client-to-server authority map",
    "Local data handling notes"
  ],
  "pitfalls": [
    "Trusting a client-side route as authorization",
    "Leaving deep-link state reusable",
    "Treating a configured hostname as ownership proof"
  ],
  "references": {
    "resources": [
      {
        "id": "owasp-authorization-cheat-sheet",
        "title": "Authorization Cheat Sheet",
        "url": "https://vulns.co/research/resources/owasp-authorization-cheat-sheet/"
      },
      {
        "id": "rfc-10017-browser-oauth-token-custody",
        "title": "RFC 10017: OAuth 2.0 for Browser-Based Applications",
        "url": "https://vulns.co/research/resources/rfc-10017-browser-oauth-token-custody/"
      },
      {
        "id": "owasp-security-logging-evidence-quality",
        "title": "OWASP Logging: trustworthy and minimal application evidence",
        "url": "https://vulns.co/research/resources/owasp-security-logging-evidence-quality/"
      }
    ],
    "diagrams": [
      {
        "id": "delegated-grant-authority-continuity",
        "title": "Delegated authority stays within the approved grant",
        "url": "https://vulns.co/research/diagrams/delegated-grant-authority-continuity/"
      }
    ],
    "reports": [
      {
        "id": "google-device-authorization-client-scope-binding-2026",
        "title": "Google device grants lost client and permission binding",
        "url": "https://vulns.co/research/reports/google-device-authorization-client-scope-binding-2026/"
      }
    ]
  },
  "provenance": {
    "publisher": "vulns.co / GK Data",
    "guide_updated": "2026-10-11",
    "library_as_of": "2026-10-04",
    "library_commit": "d5550c7891119cf1379e235721541c947850a3b3"
  },
  "url": "https://vulns.co/skills/mobile/",
  "markdown_url": "https://vulns.co/skills/mobile/SKILL.md"
}
