Why is Redirect URL Fully Qualified in Azure AD B2C?
Why does the redirect URL have to match completely? Wouldn't matching at the domain level be sufficient enough for proper security? What if I had hundreds of paths? example urls: https://myawesomesite.com https://myawesomesite.com/account/profile https://myawesomesite.com/games/fungame/points https://www.myawesomesite.com/games/fungame/points ... I would have to enter the 4 above redirect urls into my B2C app configuration. This is actually discussed in RFC 6819 "OAuth 2.0 Threat Model and Security Considerations" sections 4.1.5 , 4.2.4 and 5.2.3.5 . 4.1.5. Threat: Open Redirectors on Client