# OAuth2重定向URI不匹配允许回调拦截

- **ID:** `security/oauth2-redirect-uri-mismatch-allows-callback-interception`
- **领域:** security
- **类别:** auth_error
- **错误码:** `OAUTH2_REDIRECT_URI_MISMATCH`
- **验证级别:** ai_generated
- **修复率:** 92%

## 根因

当OAuth2授权请求中的redirect_uri与注册的回调URL不匹配时，攻击者可以通过使用他们控制的不同重定向URI来拦截授权代码。

## 版本兼容性

| 版本 | 状态 | 引入 | 弃用 |
|------|------|------|------|
| OAuth2.0 | active | — | — |
| Spring Security 5.6+ | active | — | — |
| Keycloak 21.0.0 | active | — | — |
| Okta 2023.09.0 | active | — | — |

## 解决方案

1. ```
   Register exact redirect URIs on the authorization server (e.g., https://myapp.com/callback) and validate that the request's redirect_uri matches exactly, including path and query parameters. Example in Keycloak: in client settings, set 'Valid Redirect URIs' to 'https://myapp.com/callback' without wildcards.
   ```
2. ```
   Implement strict redirect URI validation on the client side: compare the received redirect URI against a whitelist of allowed URIs before processing the authorization code.
   ```
3. ```
   Use PKCE in combination with exact redirect URI matching to prevent interception even if the redirect URI is slightly different.
   ```

## 无效尝试

- **** — Using a wildcard in the registered redirect URI (e.g., https://*.example.com) allows attackers to register a subdomain they control, intercepting the code. (75% 失败率)
- **** — Allowing redirect URIs with different paths but same host is insufficient because attackers can use a path they control (e.g., /attacker-callback). (65% 失败率)
- **** — Validating only the hostname but not the path or query parameters leaves the system vulnerable to path-based interception. (60% 失败率)
