Why is Redirect URL Fully Qualified in Azure AD B2C?
问题 Why does the redirect URL have to match completely? Wouldn't matching at the domain level be sufficient enough for proper security? What if I had hundreds of paths? example urls: https://myawesomesite.com https://myawesomesite.com/account/profile https://myawesomesite.com/games/fungame/points https://www.myawesomesite.com/games/fungame/points ... I would have to enter the 4 above redirect urls into my B2C app configuration. 回答1: This is actually discussed in RFC 6819 "OAuth 2.0 Threat Model