L32 · OAUTH 2.0
One method per client
Authenticate a confidential client the registered way, then see the token endpoint refuse a wrong secret and a secret sent the wrong way.
Planned
Steps
Request a token with curl, sending the client ID and secret in an HTTP Basic header.
What the server will check: A successful token request for your confidential client.
Send the same request with one character of the secret changed.
What the server will check: The token endpoint rejected the client.
The response does not say which part was wrong, so it gives nothing away to someone guessing.
Send the correct secret in the request body instead of the header.
What the server will check: The token endpoint refused the request.
Your client is registered for HTTP Basic. Accepting another method would give its credential a second way in.
When it opens
This lab is planned. It opens when these are in place:
- Lab setup and cleanup in your test tenant
The server checks your test tenant's history for this attempt. You can review the events yourself in your tenant's Audit and Logs.