实现免登获取code出错
这个是OAuth 的规范限制的
The OAuth 2.0 specification's authorization code mechanism includes redirect URI checking from the site you redirect to. See steps D and E in section 4.1 of the spec. Also, section 4.1.3 describes in detail that the redirected-to client needs to transmit redirect_uri, and that it needs to match that of the initial authorization request.
大意是,code 只能给发起请求的, 后台AS指定的信任redirect_uri, 防止第三方来钓鱼得到code, 进一步得到access token。
赞0
踩0