Research archive
The Identity pillar, and beyond
Every post is practitioner-tested: reproduced against a purpose-built lab, with the conditions, the logs, and the fix written down.
2026-05-16
The Gap Nobody Talks About: From "OAuth Is Attackable" to "Here's the Proof"
The series intro: why practitioner proof matters, and the reframe from auth flows to the full Zero Trust model.
2026-05-22OAuth Authorization Code Interception: The Flow, the Seam, and What Your Logs Actually Show
Authorization code interception end-to-end: what the attack looks like, where the seam is, and what it produces in logs. Reproducible against FlawedToken.
2026-07-11Redirect URI Manipulation: Stealing the Authorization Code at the Door
The redirect_uri is the load-bearing control in the OAuth authorization code flow, and it fails quietly. A red-team walkthrough.
2026-05-29The Local Lab Blueprint: Building an Isolated, Scriptable Interception Lab
A reproducible, containerized interception lab for auth-flow research — mitmproxy, Docker, and browser session containerization.