← Back to Baseline

MB-R123

HUMAN VERIFICATION REQUIRED ASVS 10.4.2 OAuth authorization codes are single-use

MB-C13 Application Behavior & Human Assurance Medium

If the authorization server returns the authorization code in the authorization response, it can be used only once for a token request. For the second valid request with an authorization code that has already been used to issue an access token, the authorization server must reject a token request and revoke any issued tokens related to the authorization code.