Q52Using APIsMultiple answers
An application has started an OAuth authorization code grant flow to obtain access to an API resource on an end user’s behalf. Which two parameters are included in the HTTP request returned to the application when the end user grants access? (Choose two.)
Select 2 answers.
← → navigate · a answer
Community votes
Discussion · 7
37
Answer is 'D & E'
D. code that can be exchanged for an access token
E. state can be used for correlation and security checks
"If the user approves the request, the authorization server will redirect the browser back to the redirect_uri specified by the application, adding a code and state to the query string."
https://developer.okta.com/blog/2018/04/10/oauth-authorization-code-grant-type
"Assuming the resource owner grants access, the authorization
server redirects the user-agent back to the client using the
redirection URI provided earlier (in the request or during
client registration). The redirection URI includes an
authorization code and any local state provided by the client
earlier."
https://tools.ietf.org/html/rfc6749
6
I agree with FR99.
It's only the auth code and state:
HTTP/1.1 302 Found
Location: {Redirect URI}
?code={Authorization Code} // - Always included
&state={Arbitrary String} // - Included if the authorization
// request included 'state'.
reference: https://darutk.medium.com/diagrams-and-movies-of-all-the-oauth-2-0-flows-194f3c3ade85
4
ANSWER IS "D" and "E"
From cisco devcor elearning 6.7 OAuth 2.0 Three-Legged Authorization Flow :
Once the user has granted permission, the authorization server will then redirect the user to the redirect URI . This redirect will also include the authorization code and the state parameter.
2
I agree with FR99 as well.
D, E 2
Selected Answer: DE
D and E
D, E 1
Selected Answer: DE
Agree with FR99
Correct answer: D & E
D. code that can be exchanged for an access token
E. state can be used for correlation and security checks
"If the user approves the request, the authorization server will redirect the browser back to the redirect_uri specified by the application, adding a code and state to the query string."
https://developer.okta.com/blog/2018/04/10/oauth-authorization-code-grant-type
"Assuming the resource owner grants access, the authorization
server redirects the user-agent back to the client using the
redirection URI provided earlier (in the request or during
client registration). The redirection URI includes an
authorization code and any local state provided by the client
earlier."
https://tools.ietf.org/html/rfc6749
D, E 1
Selected Answer: DE
The right answers are D. code that can be exchanged for an access token and E. state can be used for correlation and security checks.