--- name: oauth-oidc-flow-review description: Review authorized OAuth and OIDC flows for redirect, state, nonce, PKCE, issuer, audience, account-linking, and session-binding failures. --- # OAuth and OIDC flow review ## Accepted inputs - Current scope and controlled relying-party and identity-provider accounts - Complete browser redirect chain and redacted token metadata - Client registration, response mode, grant, and session expectations ## Procedure 1. Diagram the authorization request, user session, callback, token exchange, account link, and application session. 2. Record redirect URI, state, nonce, PKCE challenge, issuer, audience, client, subject, and token type bindings. 3. Establish a valid controlled flow and an expired or incorrect-state negative control. 4. Mutate one binding at a time and keep both browser sessions distinguishable. 5. Verify resulting identity and session state using controlled accounts, not token appearance alone. 6. Treat a redirect quirk as a lead until an artifact or identity crosses an unintended boundary. ## Output artifacts - Flow diagram and binding matrix - Redacted redirect and claim evidence - Supported identity effects and rejected mutations ## Stop conditions Stop before credential interception, uncontrolled accounts, third-party tenants, or reuse of live user artifacts. ## Completion gate Complete when a fresh controlled reproduction shows the binding failure and resulting identity effect, or each ranked mutation is rejected with a meaningful negative control.