[high] oauth-patterns: OAuth implicit grant flow detected #42
Reference in New Issue
Block a user
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
high Finding
Scanner: oauth-patterns
Severity: high
Rule: oauth-implicit-grant
Description
Implicit grant flow is deprecated and insecure. Use authorization code flow with PKCE instead.
Location
File:
compliance-agent/src/pipeline/patterns.rs(line 340)Code
Fingerprint:
f857d4e08a3c7a17033d00ba0a2edc31d0b7170b10f1f2dab631ab9577a47e0aGenerated by compliance-scanner
Labels: severity:high, scanner:oauth-patterns, compliance-scanner