# OAuth2令牌重用检测失败允许重放攻击

- **ID:** `security/oauth2-token-reuse-detection-failure-allows-replay-attack`
- **领域:** security
- **类别:** auth_error
- **错误码:** `OAUTH2_TOKEN_REUSE_DETECTION_FAILURE`
- **验证级别:** ai_generated
- **修复率:** 89%

## 根因

当授权服务器未跟踪授权代码或访问令牌是否已被使用时，攻击者可以重放捕获的令牌以获得未经授权的访问。

## 版本兼容性

| 版本 | 状态 | 引入 | 弃用 |
|------|------|------|------|
| OAuth2.0 | active | — | — |
| Spring Security 5.6+ | active | — | — |
| Keycloak 22.0.0 | active | — | — |
| Auth0 2024.02 | active | — | — |

## 解决方案

1. ```
   Implement token reuse detection on the authorization server: store a flag or timestamp for each authorization code and access token, and reject requests that use an already-used code or token. Example in Spring Security: configure OAuth2AuthorizationService with a persistent store that marks codes as used.
   ```
2. ```
   Use short-lived authorization codes (e.g., 1 minute) and access tokens (e.g., 5 minutes) combined with reuse detection to minimize the replay window.
   ```
3. ```
   Implement token binding (e.g., via DPoP or mTLS) to tie tokens to a specific client, preventing replay from other clients.
   ```

## 无效尝试

- **** — Relying on short token lifetimes (e.g., 5 minutes) does not prevent replay within that window; an attacker can replay the token immediately after capture. (70% 失败率)
- **** — Using a nonce in the request is insufficient if the authorization server does not track nonces per token; an attacker can reuse the same nonce. (60% 失败率)
- **** — Encrypting the token does not prevent replay because the attacker can still send the same encrypted token. (50% 失败率)
