
OAuth Callback Logs Need a Redaction Boundary
OAuth callback handlers are usually reviewed for the right reasons: state validation, PKCE, redirect URI checks, and token exchange errors. Logging often gets less attention. That is risky because the callback is where useful debugging data and highly sensitive protocol data meet.

