oauth-v2-1
oauth-v2-1 copied to clipboard
Security consideration of size of client parameters
An attacker could pass a client generated parameter that is too long for the server potentially. Should this be mentioned in security considerations, or would that be considered a general web security consideration and not need mentioning?