In case you needed a reminder about why we care so much about OAuth/OIDC flows being used in the system browser and not embedded browsers, Instagram injects their own tracking code in every web page you visit inside Instagram krausefx.com/blog/ios-privac…

Aug 10, 2022 · 6:46 PM UTC

3
18
1
51
Replying to @aaronpk
And of course Twitter opens the link in an in-app browser:-)
1
2
1
4
Oof yeah. At least they give you a button to pop out to the real browser easier.
2
Replying to @aaronpk
Although if it is a first party oauth integration (where one company controls the mobile app, the APIs, and, through a legal contract the Authorization Server), this injection is less of an issue, right?
1
This particular issue isn't really a problem if you control the app and AS, but there are other reasons not to embed the AS page in an in-app web view.
1
1