Is Plain PKCE downgrade detected

Attackers can downgrade PKCE protection without the server noticing. The authorization request used S256 PKCE, but an attacker can downgrade this to plain PKCE by modifying the token request.

View source code on GitHub


This test is part of the following document(s):

Back to the test case overview or the threat overview